HomeControl Library › 3.5.5
3.5 Identification & Authentication1 ptPOA&M-eligible

3.5.5 — Don't recycle identifiers

Prevent reuse of identifiers for a defined period.

User and account IDs aren't reassigned for a defined period.

What it actually means

When someone leaves, their username/identifier shouldn't be handed to a new person right away — reuse muddies your audit trail. Define a non-reuse period and let your identity provider enforce it.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library