Skip to main content

πŸ’Ό 8.5 Do not use group, shared, or generic IDs, passwords, or other authentication methods.

Description​

As follows:

  • Generic user IDs are disabled or removed.
  • Shared user IDs do not exist for system administration and other critical functions.
  • Shared and generic user IDs are not used to administer any system components.

Similar​

  • Sections
    • /frameworks/pci-dss-v4.0/08/02/02
  • Internal
    • ID: dec-c-c33bf83a

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 8.2.2 Group, shared, or generic accounts, or other shared authentication credentials are only used when necessary on an exception basis.1

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 8.2.2 Group, shared, or generic accounts, or other shared authentication credentials are only used when necessary on an exception basis.1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό 8.5.1 Service providers with remote access to customer premises must use a unique authentication credential for each customer.

Policies (1)​

PolicyLogic CountFlags
πŸ“ AWS Account Root User credentials were used is the last 30 days πŸ”΄πŸŸ’1πŸ”΄ x1, 🟒 x6

Internal Rules​

RulePoliciesFlags
βœ‰οΈ dec-x-e58fd8e01