Q51
Single choice
While assessing an OSC, you realize they have given identifiers to systems, users, and processes.
Examining their documentation, you know they have assigned accounts uniquely to employees,
contractors, and subcontractors. The OSC has an automated system that disables any identifiers that are left unused for 6 months. You also learn from interviewing IT security administrators that the OSC has defined a technical and documented policy where identifiers can only be reused after 12 months.
How is the OSC likely to consider CMMC practice IA.L2-3.5.5 - Identifier Reuse if you find issues with its implementation?