PCI DSS 4.0
Req 7: Restrict Access by Need to Know

PCI DSS 4.0 7.2.4: 7.2.4 User accounts and privileges reviewed every six months

All user accounts and their related access privileges, including third-party and vendor accounts, must be reviewed at least every six months. The review must confirm that accounts and access remain appropriate for each person's job function, any inappropriate access must be dealt with, and management must acknowledge that the remaining access is appropriate. The guidance notes the review is also a chance to catch terminated users and third parties whose access was missed. Applicability: covers every user account and related privilege, including accounts of personnel, of vendors and of other third parties and accounts used to reach third-party cloud services; application and system accounts are handled instead by Requirement 7.2.5 (and its sub-requirement) and by 8.6.1 to 8.6.3. Objective under the customized approach: management periodically verifies that account privilege assignments are correct and remediates nonconformities. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 120 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 16 controls

  • AC-2 Account Management
  • AC-2(1) Automated System Account Management
  • AC-2(7) Privileged User Accounts
  • AC-21 Information Sharing
  • AC-22 Publicly Accessible Content
  • AC-5 Separation of Duties
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(5) Privileged Accounts
  • AC-6(7) Review of User Privileges
  • CM-12 Information Location (CM-12)
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5))
  • IA-4(4) Identifier Management | Identify User Status (IA-4(4))
  • MA-3 Maintenance Tools (MA-3)
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer
  • RA-5(5) Privileged Access

FedRAMP Moderate · 16 controls

  • AC-2 Account Management
  • AC-2(1) Automated System Account Management
  • AC-2(7) Privileged User Accounts
  • AC-21 Information Sharing
  • AC-22 Publicly Accessible Content
  • AC-5 Separation of Duties
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(5) Privileged Accounts
  • AC-6(7) Review of User Privileges
  • CM-12 Information Location (CM-12)
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5))
  • IA-4(4) Identifier Management | Identify User Status (IA-4(4))
  • MA-3 Maintenance Tools (MA-3)
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer
  • RA-5(5) Privileged Access

HIPAA Security Rule · 9 controls

NIST SP 800-53 Rev 5 · 9 controls

NIST SP 800-66 Rev 2 · 9 controls

SOC 2 · 9 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-P5.1 P5.1 Data subject access
  • SOC2-P6.7 P6.7 Accounting of personal information held and disclosed
  • SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications

CIS Controls v8 · 8 controls

  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.3 Disable Dormant Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-5.6 Centralize Account Management
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control

CMMC 2.0 · 7 controls

ISO 27001:2022 · 6 controls

  • 5.16 Identity management
  • 5.18 Access rights
  • 5.3 Segregation of duties
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.2 Privileged access rights
  • 8.3 Information access restriction

ISO 27002:2022 · 6 controls

  • 5.15 Access control
  • 5.16 Identity management
  • 5.18 Access rights
  • 5.34 Privacy and protection of PII
  • 8.2 Privileged access rights
  • 8.3 Information access restriction

ISO 27701:2019 · 4 controls

  • 6.6 Access control
  • 6.6.1 Business requirements of access control
  • 6.6.2 User access management
  • 7.4.4 PII minimization objectives
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources
  • ASBv3-PA-4 Review and reconcile user access regularly
  • PA-3 Manage lifecycle of identities and entitlements

NIST SP 800-171 Rev 3 · 2 controls

  • P1-5.1.3 P1-5.1.3 Least privilege by job function, reviewed periodically
  • P2-4.3.4 P2-4.3.4 Remote access privileges reviewed at least quarterly
  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • ASD37-18 Restrict administrative privileges (Essential)

C5 (Germany) · 1 control

NIST SP 800-172 · 1 control

UK Cyber Essentials · 1 control

  • CE-AC.6 Periodic Review of Privileged Access

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 7: Restrict Access by Need to Know

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 7.2.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 120 it maps to, and the evidence behind each claim, over MCP and REST.