Rationale
Service accounts are attractive targets for hackers because of their often high privileges.
Bad Practices
Leave unnecessary service accounts
Implementation Details
- Provide examples of typical unnecessary native service accounts
Quotes
Both hackers and security pros strongly agree that service accounts are an attractive target because hackers can easily elevate privileges and gain access to sensitive information.
(…)
Service accounts can pose a significant risk to organizations because they are so difficult to manage and secure properly, especially across multiple accounts for different services, tasks, and other applications. These accounts are time consuming to control and prone to human error when managed manually. Service account passwords are also a challenge: administrators can’t safely change a service account password if they don’t know where it’s used without risk of bringing down other applications.
(…)
#1: Remove unnecessary service accounts
(Thycotic, 2019, p. 3)
Bibliography
Related Best Practices
…