Interactive Login

PCIComplianceHubLast updated

A person entering credentials to log in directly to an application or system account, as opposed to that account being used by the process it exists for. When a person logs in as a service account, the resulting actions are attributable to the account and not to the person.

Applies to. Every application and system account on an in-scope system component.
Example. An engineer logs in as the database service account to run a manual fix. 8.6.1 requires that to be prevented unless there is a documented, approved need, limited to the time needed, and that the engineer's individual identity is confirmed before access is granted and every action is attributable to them.
Limits. The point of the control is accountability. 10.2.1.2 requires audit logs to capture interactive use of application and system accounts, and 11.3.1.2's authenticated scanning uses such accounts without interactive login being needed. The exception process is what an assessor examines: a standing approval for 'whenever we need it' is not the documented need 8.6.1 describes.
In PCI DSS v4.0.1. 8.6.1, 10.2.1.2