Identity & Access · IA-Q09

Question

Do service accounts have named owners, least-privilege scopes, and scheduled credential rotation?

Why This Matters

Unowned service identities accumulate risky, non-rotated secrets.

Maturity

How to Level Up

| From → To | Actions | |—|—| |0 → 2| Register all service accounts; assign owners and scopes.| |2 → 3| Move secrets to a vault; scheduled rotation.| |3 → 4| Replace long-lived secrets with short-lived tokens/OIDC.| |4 → 5| Add provenance, SBOM links, and attestation checks.|

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

Common Pitfalls

Compliance Mapping