Episode 26 — Safeguard 5.3 – Disable dormant accounts episode artwork

EPISODE · Oct 18, 2025 · 10 MIN

Episode 26 — Safeguard 5.3 – Disable dormant accounts

from Framework: The Center for Internet Security (CIS) Top 18 Controls · host Jason Edwards

Safeguard 5.3 requires organizations to detect and disable dormant accounts—user identities that have not been used for an extended period, typically forty-five days or more. Dormant accounts are among the most overlooked attack vectors in enterprise environments. When active but unused, they retain system access rights and credentials that can be exploited by adversaries without immediate detection. Attackers often target such accounts to establish persistence or escalate privileges because legitimate users rarely notice unusual activity associated with them. By identifying and deactivating these accounts, enterprises dramatically reduce opportunities for unauthorized access. This safeguard enforces the principle that every active credential must serve a verified, ongoing business function, and that any account lacking such purpose should be promptly disabled or removed.Implementing this safeguard involves automation, monitoring, and governance. Identity and Access Management (IAM) platforms can generate inactivity reports based on login timestamps, flagging accounts exceeding inactivity thresholds. Integration with HR systems ensures that changes in employment status automatically trigger account deactivation. Logging and alerting systems should record and notify administrators when dormant accounts are detected or reactivated, supporting accountability and auditing. Exception processes must be documented for accounts that require extended inactivity, such as service or project-based users, with explicit justification and periodic review. Regular validation ensures that the environment remains free of stale credentials, supporting compliance and reducing insider risk. Over time, this safeguard fosters a culture of continuous hygiene—where inactive access paths are not simply ignored but systematically removed before they can become liabilities. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

Episode metadata supplied by the publisher feed · Published Oct 18, 2025

Embed this episode

Ready to play

Episode 26 — Safeguard 5.3 – Disable dormant accounts

0:00 10:36

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Framework: The Center for Internet Security (CIS) Top 18 Controls?

This episode is 10 minutes long.

When was this Framework: The Center for Internet Security (CIS) Top 18 Controls episode published?

This episode was published on October 18, 2025.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Framework: The Center for Internet Security (CIS) Top 18 Controls episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!