id: "AC-02(03)" title: "Disable Accounts" family: "AC" family_name: "Access Control" sort_id: "ac-02.03" priority: "P1" implementation_level: "system" parent: "AC-02" enhancement: True


Statement

Disable accounts within {{ insert: param, ac-02.03_odp.01 }} when the accounts:

Have expired;

Are no longer associated with a user or individual;

Are in violation of organizational policy; or

Have been inactive for {{ insert: param, ac-02.03_odp.02 }}.

Guidance

Disabling expired, inactive, or otherwise anomalous accounts supports the concepts of least privilege and least functionality which reduce the attack surface of the system.

Assessment Objective: accounts are disabled within {{ insert: param, ac-02.03_odp.01 }} when the accounts have expired;

Assessment Objective: accounts are disabled within {{ insert: param, ac-02.03_odp.01 }} when the accounts are no longer associated with a user or individual;

Assessment Objective: accounts are disabled within {{ insert: param, ac-02.03_odp.01 }} when the accounts are in violation of organizational policy;

Assessment Objective: accounts are disabled within {{ insert: param, ac-02.03_odp.01 }} when the accounts have been inactive for {{ insert: param, ac-02.03_odp.02 }}.

Access control policy

procedures for addressing account management

system security plan

system design documentation

system configuration settings and associated documentation

system-generated list of accounts removed

system-generated list of emergency accounts disabled

system audit records

system security plan

other relevant documents or records

Organizational personnel with account management responsibilities

system/network administrators

organizational personnel with information security responsibilities

system developers

Mechanisms for implementing account management functions