account management
163497·updated Aug 30, 2026An access-control discipline covering the full lifecycle of digital accounts — creation, modification, privilege assignment, monitoring, and removal — for every category of account (individual, shared, group, service, emergency, guest, anonymous, temporary, and others) across an organization's systems. It uses processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts and service accounts, across enterprise assets and software. It focuses on managing and controlling the creation, activation, modification, and termination of accounts in ways that enforce least privilege and reduce unauthorized-access risk. As an information-security-continuous-monitoring (ISCM) capability, it ensures that people have the privileges necessary — and only those necessary — to perform their duties.
Source
Account Managementthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- CIS Critical Security Control 5: Account Management
- NIST 800-53, Privileged Access Management & Least Privilege
- Capability, Privilege and Account Management - Glossary | CSRC
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
An access-control discipline covering the full lifecycle of digital accounts — creation, modification, privilege assignment, monitoring, and removal — for every category of account (individual, shared, group, service, emergency, guest, anonymous, temporary, and others) across an organization's systems. It uses processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts and service accounts, across enterprise assets and software. It focuses on managing and controlling the creation, activation, modification, and termination of accounts in ways that enforce least privilege and reduce unauthorized-access risk. As an information-security-continuous-monitoring (ISCM) capability, it ensures that people have the privileges necessary — and only those necessary — to perform their duties.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- account managements
- possessive
- account management's
- pluralpossessive
- account managements'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- An access-control discipline covering the full lifecycle of digital accounts — creation, modification, privilege assignment, monitoring, and removal — for every category of account (individual, shared, group, service, emergency, guest, anonymous, temporary, and others) across an organization's systems. It uses processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts and service accounts, across enterprise assets and software. It focuses on managing and controlling the creation, activation, modification, and termination of accounts in ways that enforce least privilege and reduce unauthorized-access risk. As an information-security-continuous-monitoring (ISCM) capability, it ensures that people have the privileges necessary — and only those necessary — to perform their duties.DR-088 backfill from the noun definition column