AC-2 (2) What is the solution and how is it implemented?
AC-2 (3) Control Enhancement (H)
The information system automatically disables inactive accounts after [FedRAMP Assignment: thirty-five (35) days for user accounts].
AC-2 (3) Additional FedRAMP Requirements and Guidance:
Requirement: The service provider defines the time period for non-user accounts (e.g., accounts associated with devices). The time periods are approved and accepted by the JAB/AO. Where user management is a function of the service, reports of activity of consumer users shall be made available.