What to Provide
A screenshot from your password vault/password manager system demonstrating all shared accounts for in-scope production systems.
Evidence Format
Screenshots or exported images in a common image file type such as .jpg, .png, or .pdf.
Additional Guidance
This evidence should demonstrate the:
Name of all shared service accounts
Name of all in-scope systems these accounts have access to
All users who have access to these shared accounts and their associated vaults
NOTE: If a password vault/password manager is not utilized to manage shared accounts, please mark this Evidence Request as N/A.
Associated Unified Control ID | Associated Framework Control |
CTRL-319 | LCL-31 |