DependencyModerate confidence
Why: Account management presumes a trustworthy answer to 'what accounts exist, and for whom?' The practice's reconciled inventory of identities, devices, and applications is the reference list against which account creation, disablement clocks, and periodic reviews are checked.
What this does not claim: An inventory neither authorizes nor disables anything. The lifecycle mechanics this requirement asks for — defined account types, disablement within defined periods, notification flows, periodic reviews — are separate work that the inventory only makes checkable. It contributes the evidence base, not the account management itself.
Practice-side activities- Reconcile identity-store accounts against personnel and asset records on a cadence
- Register service and vendor accounts with owner and purpose alongside hardware assets
Evidence this produces- Reconciliation reports between directory and inventory
- Service-account register with owners and review dates
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06
Direct implementation supportHigh confidence
Why: The practice's core activity — knowing and limiting who can touch production systems — is account management applied to the OT estate: named users, authorized accounts, and removal when access is no longer needed are the shared substance.
What this does not claim: Supports implementation of the requirement for OT scope only, and OT reality bends the mechanics: shared HMI operator accounts may be unavoidable for line operations, vendor accounts may be contractually managed, and disablement clocks must respect systems that cannot be touched mid-run. Each deviation needs documentation and a compensating measure, and the IT estate's accounts sit outside this practice entirely.
Practice-side activities- Enumerate accounts on HMIs, engineering workstations, and controllers with named owners
- Document and time-bound vendor accounts; deactivate them between service windows
- Fold OT accounts into the periodic access review with the plant leader present
Evidence this produces- OT account register with owners and purposes
- Review records showing OT accounts validated or removed
- Vendor-account activation and deactivation records
Where this holds: OT and production environments; the enterprise directory and business systems need their own account management.
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06