Frameworks / CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 / CPG-1.D CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
Account Security
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 CPG-1.D: Revoking Credentials for Departing Employees Disable accounts and revoke access for departing personnel within a defined time, typically same business day.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 88 controls across 60 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-20 Multi-factor authentication (Essential) ASD37-22 Network segmentation (Excellent) ASD37-25 Software firewall - inbound (Very Good) 27011-6.3 Awareness and Training 27011-8.2 Network security and segregation API1164-13 Business Continuity and Recovery AWWA-3.1 Network Segmentation CAT-D3-1 Preventative controls FFIEC-06 Network security and segmentation GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF IACS-UR-E26-Protect-NetworkSegmentation-Zones-Conduits-Boundary IACS UR E26 Protect Goal - Network Segmentation + Zones + Conduits + Boundary Defence + Data Diodes IEC62443-13 Network security monitoring IEEE1686-Section5.2-5.3-AuditLog-Retention-Export-Monitoring IEEE 1686 Section 5.2 + 5.3 - Audit Trail Records + Retention + Export + Supervisory Monitoring and Control + Network Security Monitoring ISO28001-PS-01 Facility Security 27010-13.1 Communications Security ISO27019-13 Network security monitoring ISO27043-27 Network security management ISO21434-27 Network security management LAOS-CC-Network-Security-Information-Security-Obligations-Article-21-Service-Provider-Duties Laos Cybercrime Network Security + Information Security Obligations + Article 21 + Service Provider Duties MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA MAS-TRM-Project-SDLC-Service-Management-Chapters-4-5-6-IT-Project-Software-Lifecycle-Change-ITIL MAS TRM Project + SDLC + Service Management + Chapters 4-6 + IT Project + Software Lifecycle + ITIL MMCL-5 Content Moderation, Removal Requests, and Lawful Access NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NISTPF-5 Protect-P Access Control (PR.AC-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-2 Cloud Architecture, Service Selection, and Tenant Isolation NISTSP145-6 Deployment Model Classification (Private, Community, Public, Hybrid) NISTSP146-4 IaaS Operational Recommendations and Workload Hardening NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers NISTSP88-8 Cloud-Resident Data, Hosted Storage, and Scope Boundaries NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance NZISM-5 Network Security, System Hardening, and Application Security ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management OMANCS-5 Network, Endpoint, System Development, and Configuration Security OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PCI-P2PE-06 Network security and segmentation PCI-PIN-06 Network security and segmentation PCI-SSF-06 Network security and segmentation PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PTESPHASE-4 Vulnerability Analysis SHAREASSESS-4 Vulnerability Management, Patching, Application Security SUPCHAIN-3 Dependency Verification and SBOM IM8-SEC.3 Network Security ISMSP-AC-04 Network Access Control TSAPIPE-2 OT/IT Network Segmentation and Access Control CPSC-CS.1 Network Security for Connected Products USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Account Security Query this from an agent The graph holds this control, the 88 it maps to, and the evidence behind each claim, over MCP and REST.