AC-2(3) Account Management | Disable Accounts
Description
Disabling expired, inactive, or otherwise anomalous accounts supports the concepts of least privilege and least functionality which reduce the attack surface of the system.
Applicability
The information resource owner, or designee, is responsible for ensuring that the risk mitigation measures described in this Control are implemented.
The intended audience for this Control includes, but is not limited to, all information resources owners and custodians.
Implementation
TAMU-CC shall disable accounts within 24 hours when the accounts:
- Have expired;
- Are no longer associated with a user or individual;
- Are in violation of organizational policy; or
- Have been inactive for 180 days.
Revision History
Last Updated: February 21, 2025
Previous Versions:
- June 29, 2023
- May 31, 2022
- March 25, 2021
- September 16, 2019