Identity & Access · IA-Q07

Question

Are shared accounts prohibited or tightly controlled with full attribution?

Why This Matters

Shared creds erase accountability and complicate investigations.

Maturity

How to Level Up

| From → To | Actions | |—|—| |0 → 3| Ban shared accounts except break-glass; rotate after use.| |3 → 4| Proxy via PAM; capture full session logs.| |4 → 5| Migrate to non-person identities and JIT tokens.|

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

Common Pitfalls

Compliance Mapping