Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

98 controls

03.05.05Identifier managementITSP.10.171Identification and authentication

Official Requirement

A. Receive authorization from organizational personnel or roles to assign an individual, group, role, service, or device identifier. B. Select and assign an identifier that identifies an individual, group, role, service, or device. C. Prevent reuse of identifiers for [Assignment: organization-defined time period]. D. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status].

Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3

In Plain English

Every identifier (username, service account name, device ID) must be formally authorized, uniquely assigned, and managed throughout its lifecycle. Identifiers must not be reused for a defined period after deactivation. The status of each identifier (active, suspended, terminated) must be tracked.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Identifier lifecycle management

Implementation steps

  1. Establish an identifier assignment process requiring management authorization before creating any account
  2. Apply naming conventions for all identifiers and configure Active Directory to prevent duplicate identifiers
  3. Retain disabled accounts for the defined non-reuse period before deletion; never reassign identifiers during the retention period
  4. Maintain an identifier status register and review quarterly to ensure all identifiers reflect current employment status

Tools / systems

Evidence artifacts

Evidence frequency: Per-event authorization; quarterly identifier status review