User and account IDs aren't reassigned for a defined period.
What it actually means
When someone leaves, their username/identifier shouldn't be handed to a new person right away — reuse muddies your audit trail. Define a non-reuse period and let your identity provider enforce it.
Pass or fail — an assessor needs a "yes" to each
- A defined identifier non-reuse period exists.
- Identifiers aren't reassigned within that period.
What to have ready
- Policy stating the non-reuse period
- Identity-provider lifecycle settings
Where teams trip up
- Immediately reusing a departed employee's username
- No defined period at all
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Identification & Authentication (3.5)
3.5.1 — Uniquely identify users, processes, and devices3.5.2 — Authenticate before access3.5.3 — Multifactor authentication (MFA)3.5.4 — Replay-resistant authentication3.5.6 — Disable dormant accounts3.5.7 — Enforce password complexity3.5.8 — Block password reuse3.5.9 — Force change of temporary passwords3.5.10 — Protect stored and transmitted passwords3.5.11 — Obscure authentication feedback