Leftover access
Control 6 of my CIS IG1 assessment is two safeguards, one for granting access and one for revoking it. I scored both Not Applicable. Both write-ups are mostly about one account, and it belonged to my son.
Not Applicable is the easiest status to write and the easiest one to hide behind. So before either row got to say it, I wanted the row to show where it came from.
Who the rows are about
6.1 asks for a documented process for granting access. 6.2 asks for a process for revoking it. They share a trigger: access changes “upon new hire or role change of a user,” and 6.2 adds termination and rights revocation to that list.
Every one of those is something that happens to a user. So the first job was counting users.
On Sep 29 I ran getent passwd on the workstation and the server, filtered to uid 1000 and up. Each came back with one account, mine. Then the services: GitHub collaborators and org memberships, Cloudflare members, Namecheap shared access, Obsidian Sync sharing. None.
I run this environment as the CEO of myself. When I make an SSH key or authorize an app, I'm provisioning a tool for my own use. No one else joins, and I don't change roles relative to myself.
On Sep 29 that was true. In April it wasn't.
The account
In April I gave my son a shell account on the MacBook I run as a server, for one remote-login test over Tailscale. He logged in 4 times, under 4 minutes total, and the test was done.
Nothing recorded what I'd granted him, for how long, or why. When the test ended, the revoke trigger fired and nothing happened. Tailscale came off my machines. The tailnet went away. His account stayed.
I found it on Sep 20, building the account inventory for 5.1. It had been dormant 148 days. What found it was listing every account in one place, which I'd never done before.
I deleted it on Sep 23 under 5.3, the dormant accounts safeguard. 6.2 notes that disabling can be the better move when you need the audit trail. I deleted anyway, because the account had no further use and that server gets retired when I build a dedicated one.
Why the rows still say Not Applicable
The account was gone before I scored Control 6. As the environment stood on Sep 29 and Oct 3, there was one user, and both safeguards are about what happens when there's more than one.
I could have stopped there. The status would have been accurate, and it would have left out the only time either control actually came up.
So each row carries the exception on record: a second person had an account, the grant was never written down, and the revocation never ran. Anyone who checks my Not Applicable against the 5.3 row finds the same account in both places. I want them to.
What reopens them
Each row also says when it stops being Not Applicable: the day another person gets an account on anything in scope. A server for family members would do it. 6.1 and 6.2 reopen together, because a grant with no revoke behind it is exactly how I ended up with a 148-day account.
The test I gave my son took 4 minutes. The account outlived it by 5 months.