account management
An access-control discipline covering the full lifecycle of digital accounts — creation, modification, privilege assignment, monitoring, and removal — for every category of account (individual, shared, group, service, emergency, guest, anonymous, temporary, and others) across an organization's systems. It uses processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts and service accounts, across enterprise assets and software. It focuses on managing and controlling the creation, activation, modification, and termination of accounts in ways that enforce least privilege and reduce unauthorized-access risk. As an information-security-continuous-monitoring (ISCM) capability, it ensures that people have the privileges necessary — and only those necessary — to perform their duties.