800-53|AC-2(3)

Title

DISABLE INACTIVE ACCOUNTS

Description

The information system automatically disables inactive accounts after [Assignment: organization-defined time period].

Reference Item Details

Category: ACCESS CONTROL

Parent Title: ACCOUNT MANAGEMENT

Family: ACCESS CONTROL

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.2 (L1) Ensure 'Maximum password age' is set to '60 or fewer days, but not 0'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
1.1.2 Ensure 'Maximum password age' is set to '60 or fewer days, but not 0'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1
1.1.3 (L1) Ensure 'Minimum password age' is set to '1 or more day(s)'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
1.1.3 Ensure 'Minimum password age' is set to '1 or more day(s)'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1
1.1.4 Ensure Guest Users are reviewed at least biweeklymicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v3.1.0
1.3.7 Ensure 'Required Password Change Period' is less than or equal to 90 daysPalo_AltoCIS Palo Alto Firewall 11 v1.0.0 L1
1.3.7 Ensure 'Required Password Change Period' is less than or equal to 90 daysPalo_AltoCIS Palo Alto Firewall 10 v1.1.0 L1
1.3.7 Ensure 'Required Password Change Period' is less than or equal to 90 daysPalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.4 Ensure Guest Users Are Reviewed on a Regular Basismicrosoft_azureCIS Microsoft Azure Foundations v2.1.0 L1
1.4.1.3 Ensure known default accounts do not existCiscoCIS Cisco ASA 9.x Firewall L1 v1.1.0
1.12 Ensure credentials unused for 45 days or greater are disabledamazon_awsCIS Amazon Web Services Foundations L1 3.0.0
1.12 Ensure credentials unused for 90 days or greater are disabledamazon_awsCIS Amazon Web Services Foundations L1 1.3.0
2.11 Lock Out Accounts if Not Currently in UseMySQLDBCIS MySQL 8.0 Enterprise Database L2 v1.3.0
2.11 Lock Out Accounts if Not Currently in UseMySQLDBCIS MySQL 8.0 Community Database L2 v1.0.0
2.13 Ensure 'sa' Login Account is set to 'Disabled'MS_SQLDBCIS SQL Server 2012 Database L1 AWS RDS v1.6.0
2.13 Ensure 'sa' Login Account is set to 'Disabled'MS_SQLDBCIS SQL Server 2012 Database L1 DB v1.6.0
2.13 Ensure 'sa' Login Account is set to 'Disabled'MS_SQLDBCIS SQL Server 2014 Database L1 DB v1.5.0
2.13 Ensure 'sa' Login Account is set to 'Disabled'MS_SQLDBCIS SQL Server 2014 Database L1 AWS RDS v1.5.0
2.13 Ensure the 'sa' Login Account is set to 'Disabled'MS_SQLDBCIS SQL Server 2016 Database L1 DB v1.4.0
2.13 Ensure the 'sa' Login Account is set to 'Disabled'MS_SQLDBCIS SQL Server 2022 Database L1 DB v1.1.0
2.13 Ensure the 'sa' Login Account is set to 'Disabled'MS_SQLDBCIS SQL Server 2019 Database L1 AWS RDS v1.3.0
2.13 Ensure the 'sa' Login Account is set to 'Disabled'MS_SQLDBCIS SQL Server 2017 Database L1 AWS RDS v1.3.0
10.5 Lock Inactive User AccountsUnixCIS Debian Linux 7 L1 v1.0.0
10.5 Lock Inactive User AccountsUnixCIS Ubuntu 12.04 LTS Benchmark L1 v1.1.0
17.1.1 (L1) Ensure 'Audit Credential Validation' is set to 'Success and Failure'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
17.1.1 Ensure 'Audit Credential Validation' is set to 'Success and Failure'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1
17.2.1 (L1) Ensure 'Audit Application Group Management' is set to 'Success and Failure'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
17.2.1 Ensure 'Audit Application Group Management' is set to 'Success and Failure'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1
18.2.2 (L1) Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
18.2.2 Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1
18.2.2 Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' (MS only)WindowsCIS Microsoft Windows Server 2008 R2 Member Server Level 1 v3.3.1
18.2.2 Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' (MS only)WindowsCIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1
18.3.2 (L1) Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' (MS only)WindowsCIS Microsoft Windows Server 2019 STIG v2.0.0 L1 MS
18.3.2 (L1) Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' (MS only)WindowsCIS Microsoft Windows Server 2016 v3.0.0 L1 MS
18.3.2 (L1) Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' (MS only)WindowsCIS Microsoft Windows Server 2016 STIG v2.0.0 L1 MS
18.3.2 Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' (MS only)WindowsCIS Windows Server 2012 R2 MS L1 v3.0.0
18.3.2 Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' (MS only)WindowsCIS Windows Server 2012 MS L1 v3.0.0
18.3.2 Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' (MS only)WindowsCIS Microsoft Windows Server 2022 STIG v1.0.0 L1 MS
18.9.46.1 (L1) Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'WindowsCIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 DC
18.9.46.1 (L1) Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'WindowsCIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 MS
18.9.46.1 Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'WindowsCIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MS
18.9.46.1 Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'WindowsCIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DC
18.10.42.1 (L1) Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'WindowsCIS Microsoft Windows Server 2016 STIG v2.0.0 L1 DC
18.10.42.1 (L1) Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'WindowsCIS Microsoft Windows Server 2019 STIG v2.0.0 L1 DC
18.10.42.1 (L1) Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'WindowsCIS Microsoft Windows Server 2016 STIG v2.0.0 L1 MS
18.10.42.1 (L1) Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'WindowsCIS Microsoft Windows Server 2019 STIG v2.0.0 L1 MS
18.10.42.1 Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'WindowsCIS Microsoft Windows Server 2022 STIG v1.0.0 L1 DC
18.10.42.1 Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'WindowsCIS Microsoft Windows Server 2022 STIG v1.0.0 L1 MS
18.10.42.1 Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2019 Standalone DC L1 vCIS Microsoft Windows Server 2019 Standalone DC L1 v1.0.0
18.10.42.1 Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2019 MS Standalone L1 v1.0.0