NIST SP 800-53 Rev. 5 · Access Control
AC-2 — Account Management
Residual access after termination. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.
Why this matters
A departed employee whose access was never switched off
When someone leaves an organization, their accounts are supposed to be disabled. In practice the human resources record and the computer system are often maintained by different people using different tools, and accounts survive departures. Those accounts are a recurring feature of real breach reports.
Why this check earns its place. It requires joining two sources that do not normally talk to each other — the staff record and the directory. That join is the work most small organizations cannot do for themselves.
- What it reads
- The organization's staff-departure records joined to its user directory.
- What it reports
- Accounts still active after the person's recorded departure date.
See related public disclosures on the Signals page →
The requirement
The organization must disable or remove information system accounts when an individual is terminated, transferred, or otherwise no longer requires access, within an organization-defined time period.
NIST SP 800-53 Rev. 5 — AC-2 (Account Management).
NIST states the objective. The authoritative lifecycle source, the subject-matching identifier, the permitted grace period, and the exception workflow are all organization-defined — not NIST-prescribed values.
What a check finds
Identity still enabled after the recorded termination date, with no unexpired access extension.
Choose your platform
CISA performance goals
- 3.D — Revoke credentials for departing staff
What a result does not prove
An enabled account does not by itself establish unauthorized access or a control failure. Identifier quality, export timing, and accounts held in other directories all remain contextual.