CIS Controls CIS-5.3

Delete or disable any dormant accounts after a period of 45 days of inactivity, where supported.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-5.3 Disable Dormant Accounts mitigates T1110.004 Credential Stuffing
Comments
Disabling dormant accounts removes stale accounts that may still have breached or reused credentials, reducing credential-stuffing success against abandoned identities.
References
CIS-5.3 Disable Dormant Accounts mitigates T1078.004 Cloud Accounts
Comments
Disabling inactive cloud/SaaS accounts removes abandoned identities usable for access, persistence, or privilege abuse.
References
CIS-5.3 Disable Dormant Accounts mitigates T1078.003 Local Accounts
Comments
Disabling inactive local accounts reduces stale local credential abuse, dependent on endpoint/server coverage.
References
CIS-5.3 Disable Dormant Accounts mitigates T1078.002 Domain Accounts
Comments
Dormant domain accounts can retain broad access; disabling them removes stale domain credentials from the attack surface.
References
CIS-5.3 Disable Dormant Accounts mitigates T1078 Valid Accounts
Comments
Disabling stale accounts removes valid authentication paths available to adversaries.
References
CIS-5.3 Disable Dormant Accounts mitigates T1078.001 Default Accounts
Comments
Disabling stale accounts removes valid authentication paths available to adversaries.
References