Diff: FAQ #1066
Can you define "Inactive User" as used in PCI DSS requirement 8.5.5?
Earlier Version
Later Version
Removed
Added
An inactive user account is one whose accountthat has not been used in over 90 days. NoteInactive accounts are often targets for attackers since they are generally not monitored, and changes to the accounts (such as a changed password) could easily go unnoticed.
Removing or disabling inactive accounts reduces the risk thatsectionthey 8.5will requirementsbe only applyused to “non-consumergain users” or those individuals thatunauthorized access systems withinto the cardholderenvironment.
(Note:environment,PCI includingDSS butRequirement notnumbers limitedrefer to employees,PCI contractors,DSS administrators,version and other third parties.3)
Removing or disabling inactive accounts reduces the risk that
(Note:
Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.