NIS2 · French ReCyF · Identification

NIS2 and the French ReCyF: identify users and control account lifecycles

Control starts with an explicit link between access and a person or automated process. This page explains the identification part of objective 10 of France’s ReCyF and its translation into lifecycle processes.

It belongs to the NIS2 identity and access use case, which places this workstream in the complete control chain.

  • Intended outcome

    A distinct identifier for each user or automated process, a known owner and rapid neutralisation when an account is no longer needed.

  • How to industrialise it

    Connect an authoritative source to the identity repository, Joiner / Mover / Leaver workflows and target systems.

Separate account types and responsibilities

An individual account maps to an identifiable person. A technical account serves a program, application, service or script; its purpose and owner must remain identifiable even though no human should handle its secret like a personal password.

Unused, inactive or orphaned accounts reveal a governance break. Deactivation is often preferable to deletion where traces, keys or related data must be retained under applicable rules.

Turn lifecycle into an IAM workstream

An HR source or another authoritative repository feeds the identity repository. Joiner / Mover / Leaver events can then trigger provisioning, recalculation, suspension, reactivation or deprovisioning under documented rules.

Integrating reference sources prevents a departure or change from depending on a forgotten ticket. It also requires technical-account owners, orphan and inactive-account detection, and an event log recording decisions.

Evidence to retain

  • Inventory of identities, individual accounts and technical accounts
  • Owner, purpose and system for every technical account
  • History of creations, changes, suspensions and deactivations
  • Results of orphaned and inactive-account checks

Relevant capabilities and concepts

Related controls

Sources and guidance

Turn the control into a process

Frame responsibilities, events and evidence before selecting the mechanisms to deploy.