PlumbTrackLive demoGRC Risk System

← internal audit

Audit — AC-2 — Account Management

Framework: NIST SP 800-53 Rev.5 AC-2 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Obtain the account inventory and confirm it enumerates every account type in use (individual, group, system/service, application, guest/anonymous, emergency, and temporary) with a named owner assigned to each; reconcile the inventory against the authoritative directory/identity source to confirm completeness (CIS v8 5.1, 5.5).
Examine For a sample of newly created accounts, confirm a documented access request and approval by the authorized manager/system owner exists and predates account provisioning, and that the privileges granted match what was approved (CIS v8 6.1).
Test Select a sample of dormant accounts and confirm the system automatically disables accounts after the organization-defined inactivity threshold (e.g., 45 days); if feasible, hold a test account idle past the threshold and observe it being disabled (CIS v8 5.3).
Examine For a sample of employees terminated or transferred in the review period, confirm their accounts were disabled or removed and access revoked within the organization-defined timeframe/SLA after the personnel action (CIS v8 6.2).
Examine Confirm periodic account recertification is performed at the defined frequency, with dated evidence that account owners/managers reviewed and re-attested to continued need for each account, and that flagged accounts were removed.
Interview Ask account managers to describe how they are notified of terminations, role changes, transfers, and changes in need-to-know, and how those notifications trigger account modification or removal.
Examine Confirm that temporary and emergency accounts are configured with automatic expiration/removal on a defined date rather than relying on manual cleanup.