IA.L2-3.5.6 Identifier Handling
Disable identifiers after a defined period of inactivity.
Source: NIST SP 800-171 Rev 2 3.5.6
Discussion: Inactive identifiers pose a risk to organizational information because attackers may exploit an inactive identifier to gain undetected access to organizational devices. The owners of the inactive accounts may not notice if unauthorized access to the account has been obtained.
Assessment Objectives:
Determine if:
- [a] a period of inactivity after which an identifier is disabled is defined; and
- [b] identifiers are disabled after the defined period of inactivity.
Examine: [SELECT FROM: Identification and authentication policy; procedures addressing identifier management; procedures addressing account management; security plan; system design documentation; system configuration settings and associated documentation; list of system accounts; list of identifiers generated from physical access control devices; other relevant documents or records].
Interview: [SELECT FROM: Personnel with identifier management responsibilities; personnel with information security responsibilities; system or network administrators; system developers].
Test: [SELECT FROM: Mechanisms supporting or implementing identifier management].
SPRS Score: 1
POA&M Allowed: Yes