Service Account
What is Service Account?
A non-human account used by applications, services, and automated processes to authenticate and interact with other systems and services.
Frameworks that govern service account
What the standards actually require on service account
Requirements naming service account across 6 standards, quoted from the control text.
Service accounts configured with an SPN use the Advanced Encryption Standard for encryption.
ISM-2010 · Service accounts configured with an SPN use the Advanced Encryption Standard for encryptio →Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose.
CIS-5.5 · Establish and Maintain an Inventory of Service Accounts →All ML1 requirements plus: Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated. Privileged access to systems and applications is disabled after 45 days of inactivity.
E8-ADMIN-ML2 · Restrict Administrative Privileges (ML2) →Implement least-privilege identity and access management for SCADA users, engineers, vendors, and service accounts.
API1164-06 · Access Control →Establish procedures for provisioning, reviewing, and revoking user accounts including shared and service accounts.
AWWA-2.3 · Account Management →Each user and service account uses unique credentials; shared accounts are prohibited except where technically unavoidable and compensated.
CPG-1.C · Unique Credentials →Questions people ask about service account
What is Service Account?
Why is Service Account important for compliance?
Which compliance frameworks address Service Account?
Where can I learn more about Service Account?
See how Service Account applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.