8.2 User identification and accounts are managed
How to meet it
Assign unique IDs, no shared accounts, and remove access promptly on departure.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 8.2, in plain English.
8.2.1Every user gets a unique ID before being allowed access to system components or cardholder data.
8.2.2Shared, group, or generic IDs are used only by exception, justified, approved, time-limited, and traceable to a person.
8.2.3Service providers with remote access to customer premises use a different authentication factor per customer site.
8.2.4Adding, deleting, and changing IDs and authentication factors is properly approved and limited to approved privileges.
8.2.5Access for terminated users is revoked immediately.
8.2.6Inactive user accounts are removed or disabled within 90 days.
8.2.7Third-party remote-access accounts are enabled only when needed, disabled when not, and monitored.
8.2.8After 15 minutes of idle time, a user must re-authenticate to resume the session.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Cryptography and key management policyUse for ISO 27001 A.8.24, secure authentication, encryption, SOC 2 Security, and PCI DSS encryption requirements.Password and authentication policyUse for ISO 27001 A.5.17, A.8.5, SOC 2 Security, and PCI DSS requirement 8 authentication controls.
Open the control-to-policy map← 8.1 Processes and mechanisms are defined and understood8.3 Strong authentication is established and managed →
Back to Requirement 8, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.