Accountability should sit with the organisation’s asset owners, security leadership, and operational teams that govern onboarding, visibility, and remediation. When unmanaged devices are tolerated, the business inherits the risk because no one can prove control coverage. Mature governance requires clear ownership for discovery, classification, and removal or acceptance of the exposure.
Why This Matters for Security Teams
Unmanaged devices create an accountability gap because no control owner can reliably prove where the device is, what it can reach, or whether it has been remediated. That turns a technical visibility problem into a governance failure. Current guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls and the NIST Cybersecurity Framework 2.0 places ownership on asset management, access control, and continuous monitoring functions rather than on the device itself.
For NHIs and related machine access, the same logic applies: if a laptop, VM, kiosk, contractor endpoint, or lab device remains outside security controls, the organisation cannot attest to the integrity of the identities, secrets, or sessions it uses. NHIMG research on the Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs and the Top 10 NHI Issues shows that lifecycle ownership, not just tooling, determines whether exposure is contained or ignored. In practice, many security teams discover unmanaged-device risk only after an incident review reveals that no one had explicit responsibility for discovery, enrollment, or retirement.
How It Works in Practice
Accountability should be assigned across three layers: asset ownership, security control ownership, and operational execution. Asset owners decide whether a device is permitted to exist in the environment. Security leadership defines the baseline controls it must satisfy, including inventory, endpoint posture, authentication, and monitoring. Operational teams then enforce onboarding, quarantine, exception handling, and removal. This is where governance becomes measurable rather than symbolic.
In practice, unmanaged-device control depends on a small set of repeatable mechanisms:
- Discovery that identifies devices before they are trusted with access.
- Classification that distinguishes approved, unknown, and explicitly excepted devices.
- Conditional access or network segmentation that blocks anything without posture evidence.
- Secret and credential protection so unmanaged endpoints cannot retain long-lived access.
- Documented exception handling with expiry dates, approvers, and compensating controls.
This model aligns with NIST SP 800-53 Rev 5 Security and Privacy Controls around inventory, access enforcement, and continuous monitoring, and with NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives, which frames unmanaged identities and devices as an auditability problem as much as an exposure problem. Where organisations struggle is not policy design but enforcement drift: a device may be known to one team, tolerated by another, and invisible to the monitoring stack. These controls tend to break down when remote work, BYOD, lab systems, or acquisition-heavy environments create overlapping ownership and inconsistent enrollment standards.
Common Variations and Edge Cases
Tighter device control often increases onboarding friction and support overhead, requiring organisations to balance user convenience against provable security coverage. That tradeoff is real, especially in environments that mix employee endpoints, contractor laptops, IoT, and legacy systems.
Guidance is straightforward for corporate-managed devices, but it becomes less settled for exception-heavy cases. Current guidance suggests that any device without security controls should be treated as untrusted until it is enrolled, but there is no universal standard for how long a temporary exception may remain open. Some organisations use risk acceptance with expiration, while others route unmanaged devices into a restricted network segment until remediation is complete.
Two NHIMG references are especially useful here: NHI Lifecycle Management Guide for ownership and process design, and Ultimate Guide to NHIs — Key Challenges and Risks for the consequences of incomplete visibility. The practical edge case is a device that is unmanaged but still operationally necessary, such as a vendor-maintained appliance or a recovery system. In those cases, accountability shifts to the business owner of the exception, who must prove compensating controls and a retirement plan. If that owner does not exist, the device is effectively operating on borrowed trust.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.AM | Unmanaged devices are an asset inventory and ownership failure. |
| NIST SP 800-53 Rev 5 | CM-8 | Configuration and inventory controls govern unmanaged endpoints. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Unmanaged devices often expose NHI credentials and weak lifecycle control. |
| CSA MAESTRO | GOV-01 | Agentic and machine-access governance depends on clear operational ownership. |
| NIST AI RMF | GOVERN | AI governance principles apply when unmanaged devices host autonomous workloads. |
Define accountable owners for onboarding, exceptions, and retirement of unmanaged devices.
Related resources from NHI Mgmt Group
- How should security teams enforce access controls when employees use managed and unmanaged devices for web apps?
- Who is accountable for ensuring deception controls meet federal security requirements in regulated cloud workloads?
- Who is accountable for email security decisions when organisations run both gateway and API-based controls?
- What breaks when unmanaged devices are allowed into internal apps without session controls?