1Overview
IA.L2-3.5.6 clears away dormant identities. It requires that the organization disable identifiers after a defined period of inactivity, so that accounts no longer in use do not linger as unguarded entry points. It is a one-point requirement and may be deferred on a plan of action.
An inactive account is a quiet liability. It is not watched, its password may be stale, and its owner may have left, yet it retains its access, making it an attractive target for an attacker who wants a foothold no one is monitoring. This control asks the organization to define a period of inactivity after which an identifier is disabled, and to disable identifiers accordingly, so that access follows actual use and dormant accounts are closed before they become a problem.
Disable identifiers after a defined period of inactivity.
The requirement has two parts: define the inactivity period and disable identifiers after it. The period is set by the organization to balance security against operational disruption, and once an identifier has been inactive that long, it is disabled. This is often automated through the directory, which can flag or disable accounts that have not been used within the period, so dormant identities are closed without relying on someone to notice them.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.5.6 into two objectives: define the inactivity period and disable identifiers after it.
A period of inactivity after which an identifier is disabled is defined. The organization has set how long an account can be idle before it is disabled.
Identifiers are disabled after the defined period of inactivity. Inactive identifiers are actually disabled.
The two objectives are the definition and the disabling. The common gap is at objective [b], where a period is defined but nothing actually disables inactive accounts, so dormant identities persist. The assessor looks for inactive identifiers actually being disabled.
3Failure Patterns
The failures are about dormant accounts left enabled and periods that are not enforced.
Dormant accounts left active
Accounts of departed staff or unused service identities left enabled are unmonitored entry points. Disabling them after the defined inactivity period removes that exposure.
Period defined but not enforced
A defined inactivity period with no mechanism to act on it leaves objective [b] unmet. Automated disabling through the directory is the usual way to enforce it.
No monitoring of inactivity
Without tracking account inactivity, the organization cannot know which identifiers have crossed the period. Inactivity monitoring is what makes disabling possible.
4Ownership
This is an IT-owned technical control, usually automated through the directory.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Configures inactivity monitoring and disables identifiers after the defined period. Owns the technical evidence. |
| Security or compliance lead | Defines the inactivity period and confirms inactive identifiers are actually disabled. |
| Program lead | Reviews disabled and dormant accounts periodically and retains the evidence. |
5Tooling
The control is delivered by directory inactivity monitoring and automated disabling.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Defined inactivity period | The threshold after which identifiers are disabled. |
| [b] | Directory inactivity detection, automated disable | Disabling of identifiers inactive beyond the period. |
The caveat is that a defined period does nothing without a mechanism to act on it. Automated disabling based on last activity is what satisfies objective [b], since manual review tends to miss dormant accounts. The assessor examines whether inactive identifiers are actually disabled, so the enforcement mechanism has to be present.
6Evidence
The satisfied version of 3.5.6 shows a defined period and inactive identifiers disabled.
| Evidence | What it demonstrates |
|---|---|
| Defined inactivity period | Objective [a]. The threshold for disabling. |
| Disable configuration or records | Objective [b]. Inactive identifiers actually disabled. |
The evidence should show a defined inactivity period and evidence that inactive identifiers are disabled after it. The configuration or records of disabled accounts are the clearest demonstration of the control.
An unused account is an unwatched door
Dormant identifiers keep their access while no one monitors them, and this control asks for inactive accounts to be disabled after a defined period. Automating that disable through the directory is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.5.6. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.5.6[a] and 3.5.6[b]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov