Identity & Access · IA-Q08

Question

Are dormant/inactive accounts automatically disabled or removed after defined thresholds?

Why This Matters

Dormant accounts are easy targets; time-boxing and automation reduce exposure.

Maturity

How to Level Up

| From → To | Actions | |—|—| |0 → 2| Define thresholds per risk; publish SOP.| |2 → 3| Automate disable jobs; owner notifications.| |3 → 4| Auto-delete where safe; dashboard exceptions.| |4 → 5| Add UEBA to detect stale-but-active accounts.|

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

Common Pitfalls

Compliance Mapping