account manager
An organizational role — a designated person or position formally assigned responsibility for the lifecycle governance of one or more access accounts. It is distinguished from a generic administrator or supervisor by its explicit, policy-mandated accountability: the account manager is the named party whom the organization must notify when accounts are no longer needed, when users are terminated or transferred, or when need-to-know changes, and who is responsible for ensuring accounts are created, modified, enabled, disabled, and removed in accordance with organizational policy. In practice, NIST SP 800-53 AC-2 requires organizations to assign account managers who manage accounts and roles, and automated account management mechanisms are expected to notify account managers when an account is created, enabled, modified, disabled, or removed, or when users are terminated or transferred. The role is not confined to system accounts: AC-2 requires the organization to manage information system accounts across their full lifecycle — defining account types, assigning account managers, establishing conditions for group and role membership, creating, enabling, modifying, disabling, and removi
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- An organizational role — a designated person or position formally assigned responsibility for the lifecycle governance of one or more access accounts. It is distinguished from a generic administrator or supervisor by its explicit, policy-mandated accountability: the account manager is the named party whom the organization must notify when accounts are no longer needed, when users are terminated or transferred, or when need-to-know changes, and who is responsible for ensuring accounts are created, modified, enabled, disabled, and removed in accordance with organizational policy. In practice, NIST SP 800-53 AC-2 requires organizations to assign account managers who manage accounts and roles, and automated account management mechanisms are expected to notify account managers when an account is created, enabled, modified, disabled, or removed, or when users are terminated or transferred. The role is not confined to system accounts: AC-2 requires the organization to manage information system accounts across their full lifecycle — defining account types, assigning account managers, establishing conditions for group and role membership, creating, enabling, modifying, disabling, and removiDR-088 backfill from the noun definition column