← PCI DSS 4.0.1 · Req 8 — Identify and authenticate
8.6 — System and application accounts are managed
Requirement
System and application accounts that can be used interactively are managed, their use is exception-based and attributable, and their passwords or secrets are not hard-coded in scripts, configuration files or source code and are changed periodically.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Finding any of these outranks coverage — a policy that admits the gap is worse than silence.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| ISO 27001 | A.5.15 | Access control | authentication |
| ISO 27001 | A.5.17 | Authentication information | authentication |
| ISO 27001 | A.8.2 | Privileged access rights | privileged-access |
| ISO 27001 | A.8.5 | Secure authentication | authentication |
| HIPAA | 164.308(a)(3)(ii)(A) | Authorisation and supervision (A) | privileged-access |
| HIPAA | 164.312(a)(1) | Access control — unique identification and emergency access (R/A) | authentication |
| HIPAA | 164.312(d) | Person or entity authentication (R) | authentication |
| GLBA | 314.4(c)(5) | Multi-factor authentication for any individual accessing information systems | authentication |