AC-2 Account management
Requires accounts to be managed across their full life cycle: permitted and prohibited account types defined, account managers assigned, membership prerequisites and approvals required, accounts created, modified, disabl
5
artefacts
3
held by a system
1
at each review
easy
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Provisioning and deprovisioning tickets carrying documented approval by the responsible party · Identity provider / directory
- Leaver reconciliation between the human resources record and account disablement dates · Identity provider / directory
- Monitoring output for atypical account usage and for dormant accounts · Identity provider / directory
periodic reviewEvidence produced at each review
- Periodic account recertification results with evidence that revocations were executed · Identity provider / directory
governing documentDocuments that govern the control
- Account type register showing which account types are permitted and which are prohibited · Policy repository / GRC workspace
First move
Automate the pull from your Identity provider / directory. Scheduled export of users, roles and MFA state from the directory; access-review completion pulled from the IdP, not a spreadsheet.
Common gaps auditors find
- Shared and service accounts sit outside the joiner mover leaver process entirely
- Recertification is signed off in bulk without any account actually being removed
- Contractor and third party accounts outlive the engagement because no end date is held
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAC-1 Access control policy and procedures · AC-3 Access enforcement