Skip to content

Service Account

What is Service Account?

A non-human account used by applications, services, and automated processes to authenticate and interact with other systems and services.

Information Security

What the standards actually require on service account

Requirements naming service account across 6 standards, quoted from the control text.

Service accounts configured with an SPN use the Advanced Encryption Standard for encryption.

ISM-2010 · Service accounts configured with an SPN use the Advanced Encryption Standard for encryptio
CIS Controls v82 controls

Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose.

CIS-5.5 · Establish and Maintain an Inventory of Service Accounts

All ML1 requirements plus: Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated. Privileged access to systems and applications is disabled after 45 days of inactivity.

E8-ADMIN-ML2 · Restrict Administrative Privileges (ML2)
API 11641 control

Implement least-privilege identity and access management for SCADA users, engineers, vendors, and service accounts.

API1164-06 · Access Control

Establish procedures for provisioning, reviewing, and revoking user accounts including shared and service accounts.

AWWA-2.3 · Account Management

Each user and service account uses unique credentials; shared accounts are prohibited except where technically unavoidable and compensated.

CPG-1.C · Unique Credentials

Questions people ask about service account

What is Service Account?
A non-human account used by applications, services, and automated processes to authenticate and interact with other systems and services.
Why is Service Account important for compliance?
Service Account is a key concept in Information Security. Understanding service account helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Service Account?
Service Account appears in the requirement text of Australian Information Security Manual, CIS Controls v8, ACSC Essential Eight, API 1164, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association). Across these standards we have identified 14 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Service Account?
Explore our compliance framework pages to see how service account applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Service Account applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.