PDA

View Full Version : Requirement 8.5.5 Remove unused user accounts after 90 days


Patrick
01-18-2008, 06:25 AM
Do you have to remove unused accounts that have no access to CHD?

Obviously the system needs an admin user to set up other user accounts and their permissions; I'd like to be able to keep that account open no matter how long it hasn't been used otherwise the system will be unadministrable.

Thanks

jbhall56
01-18-2008, 10:23 AM
This is a bone of contention for a lot of my clients that have significant numbers of seasonal workers that do not have access to cardholder data (CHD). These seasonal workers are not removed because they need to have access to their employers' human resources and benefit systems. However, they do not necessarily access the system every 90 days.

That said, 8.5.5 does NOT differentiate between users, it is ALL users.

To get around this, what we do is to create a compensating controls worksheet as a workaround.