Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
BETA
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon
Browse
Ctrl+K
98 controls
03.01.01Account managementITSP.10.171Access control
Official Requirement
A. Define the types of system accounts allowed and prohibited. B. Create, enable, modify, disable, and remove system accounts in accordance with organizational policy, procedures, prerequisites, and criteria. C. Specify: 1. authorized users of the system 2. group and role membership 3. access authorizations (i.e., privileges) for each account D. Authorize access to the system based on: 1. a valid access authorization 2. intended system usage E. Monitor the use of system accounts F. Disable system accounts when: 1. the accounts have expired 2. the accounts have been inactive for [Assignment: organization-defined time period] 3. the accounts are no longer associated with a user or individual 4. the accounts are in violation of organizational policy 5. significant risks associated with individuals are discovered G. Notify account managers and designated personnel or roles within: 1. [Assignment: organization-defined time period] when accounts are no longer required 2. [Assignment: organization-defined time period] when users are terminated or transferred 3. [Assignment: organization-defined time period] when system usage or the need-to-know changes for an individual H. Require that users log out of the system after [Assignment: organization-defined time period] of expected inactivity or when [Assignment: organization-defined circumstances].
Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3
In Plain English
Your organization needs to manage the full lifecycle of user accounts -- who can have one, what type, what access they get, and when accounts get disabled or removed. Every account must be approved, monitored, and reviewed regularly. When someone leaves or changes roles, their access must be promptly updated or revoked.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control System account lifecycle management
Implementation Steps
Define account types (standard user, service account, privileged, shared) in an access control policy and configure your identity provider (IdP) to enforce account categories
Automate account provisioning and deprovisioning through your IdP integrated with HR systems so that onboarding, role changes, and offboarding trigger immediate access adjustments
Configure idle session timeouts and automatic account disablement after a defined inactivity period (e.g., 90 days) in your IdP and cloud console
Schedule quarterly access reviews using your GRC or identity governance platform; document approvals and any remediation actions taken
Tools / Systems
Azure AD / Entra ID / Okta / Google Workspace (identity provider)SCIM provisioning (automated lifecycle)GRC platform (e.g., Vanta, Drata, Scrut)Cloud IAM console (AWS IAM, Azure RBAC, GCP IAM)
Typical Control System account lifecycle management
Evidence Artifacts
IdP account provisioning and deprovisioning logs showing automated lifecycle actions
Quarterly access review reports with approvals, exceptions, and remediation actions
IdP configuration screenshots showing session timeout and inactivity disablement settings