id: "AC-02(09)" title: "Restrictions on Use of Shared and Group Accounts" family: "AC" family_name: "Access Control" sort_id: "ac-02.09" priority: "P1" implementation_level: "organization" parent: "AC-02" enhancement: True


Statement

Only permit the use of shared and group accounts that meet {{ insert: param, ac-02.09_odp }}.

Guidance

Before permitting the use of shared or group accounts, organizations consider the increased risk due to the lack of accountability with such accounts.

Assessment Objective

the use of shared and group accounts is only permitted if {{ insert: param, ac-02.09_odp }} are met.

Access control policy

procedures addressing account management

system design documentation

system configuration settings and associated documentation

system-generated list of shared/group accounts and associated roles

system audit records

system security plan

other relevant documents or records

Organizational personnel with account management responsibilities

system/network administrators

organizational personnel with information security responsibilities

Mechanisms implementing management of shared/group accounts