Account

PCIComplianceHubLast updated

The identifier under which a person or a process is known to a system: a user ID, an account ID, or an application ID. It is the half of an authentication credential that says who is claiming access; the authentication factor is the half that proves it.

Applies to. Every user, administrator, application and system process on an in-scope system component. PCI DSS treats an account and the factor that authenticates it as separate things with separate rules.
Example. A payments engineer has a personal login (an account for an individual), the batch job that settles transactions runs under a service account (an application or system account), and neither is a shared or generic ID, which 8.2.2 permits only on a documented exception basis.
Limits. An account identifies; it does not by itself authenticate. The requirements on accounts (unique per user, lifecycle managed, reviewed) sit in 8.2, and the requirements on what proves the account (passwords, tokens, biometrics, MFA) sit in 8.3 and 8.4. Group and shared accounts are the case the standard restricts hardest, because an action under a shared account cannot be attributed to a person.
In PCI DSS v4.0.1. 8.2.2, 8.3.1