They often rely on fragmented processes, manual approvals, and inconsistent visibility across accounts, secrets, and privileged sessions. That creates gaps between policy and actual access. In practice, compliance fails when organisations cannot prove who has access, why that access exists, and whether it is still required for the business activity being performed.
Why Security and Compliance Teams Keep Falling Out of Sync
NIS2 and ISO 27001 both expect organisations to control access, review it regularly, and retain evidence that privileges are justified. The challenge is that modern identity estates are no longer limited to employees and contractors. Service accounts, API keys, certificates, vault entries, and agentic workloads change faster than manual review cycles can keep up. NHIM Group research shows only 5.7% of organisations have full visibility into their service accounts, which makes audit evidence difficult to produce and even harder to trust. See the Ultimate Guide to NHIs and the EU NIS2 Directive for the baseline expectations.
Where teams struggle most is not policy writing, but proving operational alignment. A policy may say access is least privilege, time-bound, and reviewed, while the actual environment still contains standing access, orphaned credentials, and exceptions that were never retired. ISO/IEC 27001 expects a working information security management system, not a one-time control statement, and current guidance suggests that evidence quality matters as much as control intent. In practice, many security teams discover the gap only during an audit request or incident review, rather than through continuous identity governance.
How Identity Controls Drift in Real Environments
Identity and access control drift usually begins with fragmented ownership. Human access is often managed in IAM, while non-human access lives in code repositories, CI/CD variables, cloud consoles, and secrets stores. That separation makes it hard to connect a privilege to a business purpose, a ticket, and a review outcome. The result is a control environment that looks compliant in policy but cannot withstand evidence testing against ISO/IEC 27001:2022 Information Security Management or ISO/IEC 27002:2022 Information Security Controls.
For NIS2, the practical issue is resilience. Organisations need to demonstrate access governance, incident readiness, and rapid containment when credentials are exposed. NHIMG’s 52 NHI Breaches Analysis and Top 10 NHI Issues show that the same failure patterns repeat: excessive privilege, weak rotation, and poor offboarding. A workable operating model usually includes:
- a complete inventory of accounts, secrets, and privileged paths
- documented ownership for every identity, including machine identities
- time-bound approvals with automatic expiry where possible
- recertification based on actual usage, not just role labels
- audit logs that show who approved access, when it was used, and when it was removed
These controls tend to break down in fast-moving DevOps and cloud-native environments because identities are created and consumed faster than review and evidence workflows can close the loop.
Where the Standard Answer Breaks Down
Tighter access governance often increases operational overhead, so organisations must balance compliance evidence against delivery speed. That tradeoff becomes sharper when teams apply human-centric processes to non-human identities, because a service account or token may exist for seconds, days, or months depending on the workload.
Best practice is evolving, but current guidance suggests separating standing human access from workload access, using short-lived credentials where possible, and making review cadence proportional to risk. The OWASP Non-Human Identity Top 10 is useful here because it frames the common failure modes around secrets sprawl, privilege misuse, and weak lifecycle controls. For organisations that rely on third parties, outsourced operations, or multiple cloud platforms, evidence collection often fails because ownership is distributed and revocation is inconsistent. In that sense, NIS2 and ISO 27001 do not usually fail on missing policy language, but on missing operational proof.
The most difficult edge case is emergency access. Break-glass accounts may be legitimate, but if their use is not logged, time-bounded, and independently reviewed, they quickly become standing exceptions that auditors will challenge. Organisations that treat every access path the same usually end up with either weak control or unworkable process, and neither supports durable compliance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity sprawl and weak visibility are core NHI governance failures. |
| NIST CSF 2.0 | PR.AC-1 | Access management depends on knowing who or what is allowed to access assets. |
| NIST AI RMF | Govern function supports accountability for automated and agentic access decisions. | |
| CSA MAESTRO | Agentic and cloud workload governance needs lifecycle controls and policy enforcement. | |
| NIST Zero Trust (SP 800-207) | Zero trust requires continuous verification instead of assumed trust for identities. |
Assign ownership for machine access decisions and require traceable approval and monitoring.
Related resources from NHI Mgmt Group
- Why do organisations struggle to keep identity governance effective during rapid growth?
- Why do organisations struggle to maintain consistent identity controls across hybrid application estates?
- How should organisations keep ISO 27001 controls effective between audits?
- Why do organisations struggle to keep cloud and AI security controls aligned as infrastructure becomes more autonomous?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org