id: "AC-02(03)" title: "Disable Accounts" family: "AC" family_name: "Access Control" sort_id: "ac-02.03" priority: "P1" implementation_level: "system" parent: "AC-02" enhancement: True
Statement
Disable accounts within {{ insert: param, ac-02.03_odp.01 }} when the accounts:
Have expired;
Are no longer associated with a user or individual;
Are in violation of organizational policy; or
Have been inactive for {{ insert: param, ac-02.03_odp.02 }}.
Guidance
Disabling expired, inactive, or otherwise anomalous accounts supports the concepts of least privilege and least functionality which reduce the attack surface of the system.
Assessment Objective: accounts are disabled within {{ insert: param, ac-02.03_odp.01 }} when the accounts have expired;
Assessment Objective: accounts are disabled within {{ insert: param, ac-02.03_odp.01 }} when the accounts are no longer associated with a user or individual;
Assessment Objective: accounts are disabled within {{ insert: param, ac-02.03_odp.01 }} when the accounts are in violation of organizational policy;
Assessment Objective: accounts are disabled within {{ insert: param, ac-02.03_odp.01 }} when the accounts have been inactive for {{ insert: param, ac-02.03_odp.02 }}.
Access control policy
procedures for addressing account management
system security plan
system design documentation
system configuration settings and associated documentation
system-generated list of accounts removed
system-generated list of emergency accounts disabled
system audit records
system security plan
other relevant documents or records
Organizational personnel with account management responsibilities
system/network administrators
organizational personnel with information security responsibilities
system developers
Mechanisms for implementing account management functions