NIS2 · French ReCyF · Identification
NIS2 and the French ReCyF: identify users and control account lifecycles
Control starts with an explicit link between access and a person or automated process. This page explains the identification part of objective 10 of France’s ReCyF and its translation into lifecycle processes.
It belongs to the NIS2 identity and access use case, which places this workstream in the complete control chain.
Intended outcome
A distinct identifier for each user or automated process, a known owner and rapid neutralisation when an account is no longer needed.
How to industrialise it
Connect an authoritative source to the identity repository, Joiner / Mover / Leaver workflows and target systems.
Separate account types and responsibilities
An individual account maps to an identifiable person. A technical account serves a program, application, service or script; its purpose and owner must remain identifiable even though no human should handle its secret like a personal password.
Unused, inactive or orphaned accounts reveal a governance break. Deactivation is often preferable to deletion where traces, keys or related data must be retained under applicable rules.
Turn lifecycle into an IAM workstream
An HR source or another authoritative repository feeds the identity repository. Joiner / Mover / Leaver events can then trigger provisioning, recalculation, suspension, reactivation or deprovisioning under documented rules.
Integrating reference sources prevents a departure or change from depending on a forgotten ticket. It also requires technical-account owners, orphan and inactive-account detection, and an event log recording decisions.
Evidence to retain
- Inventory of identities, individual accounts and technical accounts
- Owner, purpose and system for every technical account
- History of creations, changes, suspensions and deactivations
- Results of orphaned and inactive-account checks
Relevant capabilities and concepts
Identity governance
Structure sources, rules and lifecycle events.
IAM strategy and Zero Trust
Frame the roadmap, responsibilities and priorities.
Orphan account
Understand how an account loses its active identity owner.
Non-human identity
Govern service and automated-process identities.
Related controls
Access rights and recertification
Change entitlements as identity context changes.
Certificates and machine identities
Connect machine-identity ownership with cryptographic lifecycle.
Sources and guidance
ANSSI — ReCyF in practice — Identity management, version 1.0, September 2026 (French source document)
- ANSSI — IT security hygiene guide (French)
Turn the control into a process
Frame responsibilities, events and evidence before selecting the mechanisms to deploy.