PCI DSS 4.0 7.2.4: 7.2.4 User accounts and privileges reviewed every six months
All user accounts and their related access privileges, including third-party and vendor accounts, must be reviewed at least every six months. The review must confirm that accounts and access remain appropriate for each person's job function, any inappropriate access must be dealt with, and management must acknowledge that the remaining access is appropriate. The guidance notes the review is also a chance to catch terminated users and third parties whose access was missed. Applicability: covers every user account and related privilege, including accounts of personnel, of vendors and of other third parties and accounts used to reach third-party cloud services; application and system accounts are handled instead by Requirement 7.2.5 (and its sub-requirement) and by 8.6.1 to 8.6.3. Objective under the customized approach: management periodically verifies that account privilege assignments are correct and remediates nonconformities. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.
This control maps to 120 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 7.2.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.