id: "AC-02(09)" title: "Restrictions on Use of Shared and Group Accounts" family: "AC" family_name: "Access Control" sort_id: "ac-02.09" priority: "P1" implementation_level: "organization" parent: "AC-02" enhancement: True
Statement
Only permit the use of shared and group accounts that meet {{ insert: param, ac-02.09_odp }}.
Guidance
Before permitting the use of shared or group accounts, organizations consider the increased risk due to the lack of accountability with such accounts.
Assessment Objective
the use of shared and group accounts is only permitted if {{ insert: param, ac-02.09_odp }} are met.
Access control policy
procedures addressing account management
system design documentation
system configuration settings and associated documentation
system-generated list of shared/group accounts and associated roles
system audit records
system security plan
other relevant documents or records
Organizational personnel with account management responsibilities
system/network administrators
organizational personnel with information security responsibilities
Mechanisms implementing management of shared/group accounts