CCI-003624
CCI-003624 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if account managers and [AC-02_ODP[05]; personnel or roles to be notified is/are defined] are notified within [AC-02_ODP[08]; time period within which to notify account managers when system usage or the need to know changes for an individual is defined] when system usage or the need to know changes for an individual.
Validation Procedures
Examine: [SELECT FROM: Access control policy; personnel termination policy and procedure; personnel transfer policy and procedure; procedures for addressing account management; system design documentation; system configuration settings and associated documentation; list of active system accounts along with the name of the individual associated with each account; list of recently disabled system accounts and the name of the individual associated with each account; list of conditions for group and role membership; notifications of recent transfers, separations, or terminations of employees; access authorization records; account management compliance reviews; system monitoring records; system audit records; system security plan; privacy plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with account management responsibilities; system/network administrators; organizational personnel with information security with information security and privacy responsibilities]. Test: [SELECT FROM: Organizational processes for account management on the system; mechanisms for implementing account management].