Evidence of the Password Vault and Shared Accounts
Provide evidence from your password vault/password manager system showing all shared accounts for in-scope production systems.
This evidence should demonstrate the:
Name of all shared service accounts
Name of all in-scope systems these accounts have access to
All users who have access to these shared accounts and their associated vaults
Additional Guidance
If there is a shared account with access to a production system, such as a service account that only uses keys, but you have not included it in your evidence, explain why in the Evidence Description.
Related Articles
Associated Unified Control ID | Associated Framework Control |
CTRL-319 | LCL-31 |