Delete or disable any dormant accounts after a period of 45 days of inactivity, where supported.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-5.3 | Disable Dormant Accounts | mitigates | T1110.004 | Credential Stuffing |
Comments
Disabling dormant accounts removes stale accounts that may still have breached or reused credentials, reducing credential-stuffing success against abandoned identities.
References
|
| CIS-5.3 | Disable Dormant Accounts | mitigates | T1078.004 | Cloud Accounts |
Comments
Disabling inactive cloud/SaaS accounts removes abandoned identities usable for access, persistence, or privilege abuse.
References
|
| CIS-5.3 | Disable Dormant Accounts | mitigates | T1078.003 | Local Accounts |
Comments
Disabling inactive local accounts reduces stale local credential abuse, dependent on endpoint/server coverage.
References
|
| CIS-5.3 | Disable Dormant Accounts | mitigates | T1078.002 | Domain Accounts |
Comments
Dormant domain accounts can retain broad access; disabling them removes stale domain credentials from the attack surface.
References
|
| CIS-5.3 | Disable Dormant Accounts | mitigates | T1078 | Valid Accounts |
Comments
Disabling stale accounts removes valid authentication paths available to adversaries.
References
|
| CIS-5.3 | Disable Dormant Accounts | mitigates | T1078.001 | Default Accounts |
Comments
Disabling stale accounts removes valid authentication paths available to adversaries.
References
|