Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

98 controls

03.01.01Account managementITSP.10.171Access control

Official Requirement

A. Define the types of system accounts allowed and prohibited. B. Create, enable, modify, disable, and remove system accounts in accordance with organizational policy, procedures, prerequisites, and criteria. C. Specify: 1. authorized users of the system 2. group and role membership 3. access authorizations (i.e., privileges) for each account D. Authorize access to the system based on: 1. a valid access authorization 2. intended system usage E. Monitor the use of system accounts F. Disable system accounts when: 1. the accounts have expired 2. the accounts have been inactive for [Assignment: organization-defined time period] 3. the accounts are no longer associated with a user or individual 4. the accounts are in violation of organizational policy 5. significant risks associated with individuals are discovered G. Notify account managers and designated personnel or roles within: 1. [Assignment: organization-defined time period] when accounts are no longer required 2. [Assignment: organization-defined time period] when users are terminated or transferred 3. [Assignment: organization-defined time period] when system usage or the need-to-know changes for an individual H. Require that users log out of the system after [Assignment: organization-defined time period] of expected inactivity or when [Assignment: organization-defined circumstances].

Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3

In Plain English

Your organization needs to manage the full lifecycle of user accounts -- who can have one, what type, what access they get, and when accounts get disabled or removed. Every account must be approved, monitored, and reviewed regularly. When someone leaves or changes roles, their access must be promptly updated or revoked.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

System account lifecycle management

Implementation steps

  1. Document account types and approval workflows in the access control policy; maintain a request/approval process via ticketing system
  2. Use Active Directory group policies to enforce account categories, role-based groups, and automatic account expiration dates
  3. Configure Group Policy to lock workstations after inactivity and disable accounts that have not logged in within the defined period
  4. Conduct quarterly manual access reviews by exporting AD account lists and comparing against current employee roster from HR

Tools / systems

Evidence artifacts

Evidence frequency: Per-event for provisioning; quarterly access reviews; annual policy review