HomeControl Library › 3.5.6
3.5 Identification & Authentication1 ptPOA&M-eligible

3.5.6 — Disable dormant accounts

Disable identifiers after a defined period of inactivity.

Accounts unused for a set period are disabled automatically.

What it actually means

Stale accounts are easy targets and nobody's watching them. After a defined period of inactivity, identifiers should be disabled — ideally automatically through your identity provider's lifecycle policy, backed by periodic access reviews.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library