Privileged account review
The shortest fixed clock in the held texts is 4,380 hours (every six months), set by PCI DSS 7.2.4. Paste one job that feeds this consumer, for example privileged_account_review, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.
Matched on the job name or the consumer column by these words: privileged, admin account, pam report, root account, sudo review, admin review, privileged review.
The clock each rule sets
| Regime | Clock | Clause |
|---|---|---|
| PCI DSS | 4,380h | PCI DSS 7.2.4 All user accounts and related access privileges, including third-party/vendor accounts, are reviewed as follows: • At least once every six months. • To ensure user accounts and access remain appropriate based on job function.at least once every six months |
| ISO 27001 | no clock | ISO 27001 5.18 Access rights |
| SP 800-53 | no clock | SP 800-53 AC-2 Account managementa defined frequency |
Questions this page answers
How often does PCI DSS v4.0 require privileged account review?
Every six months (4,380 hours): PCI DSS 7.2.4, All user accounts and related access privileges, including third-party/vendor accounts, are reviewed as follows: • At least once every six months. • To ensure user accounts and access remain appropriate based on job function.. All user accounts and related access privileges, including third-party/vendor accounts, are reviewed as follows: • At least once every six months. • To ensure user accounts and access remain appropriate based on job function.
How often does ISO/IEC 27001:2022 require privileged account review?
The held text of ISO 27001 5.18 (Access rights) sets no fixed period: no period set by the text. Provision, review, modify and remove access rights in line with the access control policy.
How often does NIST SP 800-53 Rev 5 require privileged account review?
The held text of SP 800-53 AC-2 (Account management) sets no fixed period: a defined frequency. Requires accounts to be managed across their full life cycle: permitted and prohibited account types defined, account managers assigned, membership prerequisites and approvals required, accounts created, modified, disabled and removed under documented criteria, usage monitored, and access reauthorized on a defined frequency.
What does the register ask the owner of a privileged account review job?
Does the export include third-party and vendor accounts, as the card rule asks?
The clauses in full
All user accounts and related access privileges, including third-party/vendor accounts, are reviewed as follows: • At least once every six months. • To ensure user accounts and access remain appropriate based on job function.
What an assessor asks to see: Auditable consent records with timestamp, version, and channel. Where it usually falls short: Consent capture mechanism does not record purpose, time, and version of notice shown
Provision, review, modify and remove access rights in line with the access control policy.
Guidance beside it, ISO 27002 5.18: Requires access rights to information and other associated assets to be provisioned, reviewed, modified and removed in accordance with the organisation's topic specific policy and rules on access control.
What an assessor asks to see: access_provision_records; access_review_reports; access_revocation_logs; role_definition_documents. Where it usually falls short: Reviews lack documented corrective actions
Requires accounts to be managed across their full life cycle: permitted and prohibited account types defined, account managers assigned, membership prerequisites and approvals required, accounts created, modified, disabled and removed under documented criteria, usage monitored, and access reauthorized on a defined frequency.
What an assessor asks to see: Account type register showing which account types are permitted and which are prohibited; Provisioning and deprovisioning tickets carrying documented approval by the responsible party; Leaver reconciliation between the human resources record and account disablement dates; Periodic account recertification results with evidence that revocations were executed. Where it usually falls short: Shared and service accounts sit outside the joiner mover leaver process entirely
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register