---
name: framework-financial-services-shared-account-setup
title: IBM Cloud account setup
description: An IBM Cloud account is needed to provision and manage IBM Cloud services that make up the reference architectures of the IBM Cloud for Financial Services. Along with the high-level steps to follow, we describe some of the best practices for account setup that will help you satisfy the requirements of the IBM Cloud Framework for Financial Services. In addition, the most relevant control requirements are provided.
last-updated: 2025-03-21
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/framework-financial-services?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# IBM Cloud account setup
{: #shared-account-setup}

An [IBM Cloud account](https://cloud.ibm.com/docs/account?topic=account-overview&format=markdown) is needed to provision and manage IBM Cloud services that make up the reference architectures of the IBM Cloud for Financial Services. Along with the high-level steps to follow, we describe some of the best practices for account setup that will help you satisfy the requirements of the IBM Cloud Framework for Financial Services. In addition, the most relevant [control requirements](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-about&format=markdown#framework-control-requirements) are provided.
{: shortdesc}

1. Create an IBM Cloud account. For more information, see [Create your account](https://cloud.ibm.com/docs/account?topic=account-account-getting-started&format=markdown#account-gs-create).

   It is highly recommended that you use a functional ID that is owned by your company rather than an employee's personal ID. A functional ID is a company-owned email address (such as `ibm-cloud-admin@domain.com`) used to represent a functional user. This allows for uninterrupted administrative access by the account owner as employees leave the company or are reassigned to other projects.
   {: tip}

   The following table shows the controls that are most related to this step.

   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Access Control (AC) | [AC-2 Account Management](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-2&format=markdown)  |
   {: caption="Related controls in IBM Cloud Framework for Financial Services for account creation [FSv2.0]" caption-side="top"}
   {: #related-controls-fsv2.0}
   {: tab-title="FSv2.0"}
   {: tab-group="RelatedControls-1"}
   {: class="simple-tab-table"}


   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Access Control (AC) | [AC-2 Account Management](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-2&format=markdown)  |
   {: caption="Related controls in IBM Cloud Framework for Financial Services for account creation [FSv1.1]" caption-side="top"}
   {: #related-controls-fsv1.1}
   {: tab-title="FSv1.1"}
   {: tab-group="RelatedControls-1"}
   {: class="simple-tab-table"}


1. Set up the Activity Tracker Event Routing service as described in [Audit logging for IBM Cloud events](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-shared-logging-audit&format=markdown). This enables IBM Cloud platform events to be recorded for auditing purposes. Setting this up early in the process is important so that all platform events that occur during the rest of these steps are available in the audit logs.

   The following table shows the controls that are most related to this step.

   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Access Control (AC) | [AC-2 Account Management](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-2&format=markdown) \n [AC-2 (1) Account Management &#124; Automated System Account Management](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-2.1&format=markdown) \n [AC-2 (4) Account Management &#124; Automated Audit Actions](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-2.4&format=markdown) \n [AC-2 (7) Account Management &#124; Privileged User Accounts](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-2.7&format=markdown) |
   | Audit and Accountability (AU) | [AU-3 Content of Audit Records](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-3&format=markdown) \n [AU-4 Audit Log Storage Capacity](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-4&format=markdown) \n [AU-5 Response to Audit Logging Process Failures](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-5&format=markdown) \n [AU-6 Audit Record Review, Analysis, and Reporting](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-6&format=markdown) \n [AU-6 (1) Audit Record Review, Analysis, and Reporting &#124; Automated Process Integration](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-6.1&format=markdown) \n [AU-7 Audit Record Reduction and Report Generation](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-7&format=markdown) \n [AU-10 Non-repudiation](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-10&format=markdown) \n [AU-11 Audit Record Retention](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-11&format=markdown) |
   {: caption="Related controls in IBM Cloud Framework for Financial Services for audit logging [FSv2.0]" caption-side="top"}
   {: #related-controls-fsv2.0}
   {: tab-title="FSv2.0"}
   {: tab-group="RelatedControls-2"}
   {: class="simple-tab-table"}


   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Access Control (AC) | [AC-2 Account Management](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-2&format=markdown) \n [AC-2 (1) Account Management &#124; Automated System Account Management](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-2.1&format=markdown) \n [AC-2 (4) Account Management &#124; Automated Audit Actions](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-2.4&format=markdown) \n [AC-2 (7) Account Management &#124; Privileged User Accounts](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-2.7&format=markdown) |
   | Audit and Accountability (AU) | [AU-3 Content of Audit Records](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-3&format=markdown) \n [AU-4 Audit Log Storage Capacity](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-4&format=markdown) \n [AU-5 Response to Audit Processing Failures](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-5&format=markdown) \n [AU-6 Audit Record Review, Analysis. and Reporting](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-6&format=markdown) \n [AU-6 (1) Audit Record Review, Analysis. and Reporting &#124; Automated Process Integration](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-6.1&format=markdown) \n [AU-7 Audit Record Reduction and Report Generation](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-7&format=markdown) \n [AU-10 Non-repudiation](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-10&format=markdown) \n [AU-11 Audit Record Retention](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-11&format=markdown) |
   {: caption="Related controls in IBM Cloud Framework for Financial Services for audit logging [FSv1.1]" caption-side="top"}
   {: #related-controls-fsv1.1}
   {: tab-title="FSv1.1"}
   {: tab-group="RelatedControls-2"}
   {: class="simple-tab-table"}


1. Upgrade your account to either Pay-As-You-Go or Subscription. For more information, see [Upgrading your account](https://cloud.ibm.com/docs/account?topic=account-upgrading-account&format=markdown).

   It is highly recommended to upgrade to a Subscription account so that you can [set up an enterprise](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-shared-account-access-management&format=markdown#enterprise). Enterprises offer significant advantages in your ability to scale your environment over time as described in [Enterprise account architecture](https://cloud.ibm.com/docs/enterprise-account-architecture?topic=enterprise-account-architecture-about&format=markdown).
   {: tip}

1. Enable [multi-factor authentication (MFA)](https://cloud.ibm.com/docs/account?topic=account-enablemfa&format=markdown) for all users in your account. Choose MFA devices that align with the defined requirements. This can include hardware tokens (U2F), like FIDO2-compliant security keys, smart cards, or software tokens (TOTP). FIDO U2F standard offers the highest level of security.

   The following table shows the controls that are most related to this step.

   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Identification and Authentication (IA) | [IA-2 (1) Identification and Authentication (organizational Users) &#124; Multi-factor Authentication to Privileged Accounts](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ia-2.1&format=markdown) \n [IA-2 (6) Access to Accounts — Separate Device](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ia-2.6&format=markdown) |
   {: caption="Related controls in IBM Cloud Framework for Financial Services for multi-factor authentication [FSv2.0]" caption-side="top"}
   {: #related-controls-fsv2.0}
   {: tab-title="FSv2.0"}
   {: tab-group="RelatedControls-3"}
   {: class="simple-tab-table"}


      | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Identification and Authentication (IA) | [IA-2 (1) Identification and Authentication (Organizational Users) &#124; Multi-factor Authentication To Privileged Accounts](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ia-2.1&format=markdown) \n [IA-2 (11) Identification and Authentication (Organizational Users) &#124; Remote Access - Separate Device](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ia-2.11&format=markdown) |
   {: caption="Related controls in IBM Cloud Framework for Financial Services for multi-factor authentication [FSv1.1]" caption-side="top"}
   {: #related-controls-fsv1.1}
   {: tab-title="FSv1.1"}
   {: tab-group="RelatedControls-3"}
   {: class="simple-tab-table"}



1. Restrict IP addresses from which a user can access the IBM Cloud account. For more information, see [Allowing specific IP addresses for an account](https://cloud.ibm.com/docs/account?topic=account-ips&format=markdown#ips_account) for more information.

   The following table shows the controls that are most related to this step.

   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Access Control (AC) | [AC-4 Information Flow Enforcement](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-4&format=markdown) |
   | System and Communications Protection (SC)  | [SC-7 Boundary Protection](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-7&format=markdown) \n [SC-7 (5) Boundary Protection &#124; Deny by Default - Allow by Exception](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-7.5&format=markdown) |
   {: caption="Related controls in IBM Cloud Framework for Financial Services for restricting IP addresses [FSv2.0]" caption-side="top"}
   {: #related-controls-fsv2.0}
   {: tab-title="FSv2.0"}
   {: tab-group="RelatedControls-4"}
   {: class="simple-tab-table"}


   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Access Control (AC) | [AC-4 Information Flow Enforcement](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-4&format=markdown) |
   | System and Communications Protection (SC)  | [SC-7 Boundary Protection](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-7&format=markdown) \n [SC-7 (5) Boundary Protection &#124; Deny By Default - Allow By Exception](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-7.5&format=markdown) |
   {: caption="Related controls in IBM Cloud Framework for Financial Services for restricting IP addresses [FSv1.1]" caption-side="top"}
   {: #related-controls-fsv1.1}
   {: tab-title="FSv1.1"}
   {: tab-group="RelatedControls-4"}
   {: class="simple-tab-table"}


1. While optional, it is recommended that you [enable authentication from an external identity provider (IdP)](https://cloud.ibm.com/docs/account?topic=account-idp-integration&format=markdown) to securely authenticate external users to your IBM Cloud account. This provides a way for your employees to use your company's single sign-on (SSO) solution.

1. Enable the IBM Cloud for Financial Services Validated setting in your account. With this setting, you can [filter the catalog](https://cloud.ibm.com/catalog?search=label%3Afs_ready){: external} for services that are designated as Financial Services Validated and indicates that your account stores regulated financial services information. If you enable Financial Services Validated, your account still has access to the full public catalog. For more information, see [Enabling your account to use Financial Services Validated products](https://cloud.ibm.com/docs/account?topic=account-enabling-fs-validated&format=markdown).

   The following table shows the controls that are most related to this step.

   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Access Control (AC) | [AC-20 Use of External Systems](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-20&format=markdown) |
   | System and Services Acquisition (SA) | [SA-4 Acquisition Process](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sa-4&format=markdown) \n [SA-9 External System Services](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sa-9&format=markdown) |
   | Enterprise System and Services Acquisition (ESA) | [ESA-5 Subcontractor Risk Management](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-esa-5&format=markdown) |
   | Security Assessment and Authorization (CA) | [CA-3 Information Exchange](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ca-3&format=markdown) |
   {: caption="Related controls  in IBM Cloud Framework for Financial Services for using only Financial Services Validated services [FSv2.0]" caption-side="top"}
   {: #related-controls-fsv2.0}
   {: tab-title="FSv2.0"}
   {: tab-group="RelatedControls-5"}
   {: class="simple-tab-table"}


   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Access Control (AC) | [AC-20 Use of External Information Systems](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-20&format=markdown) |
   | System and Services Acquisition (SA) | [SA-4 Acquisitions Process](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sa-4&format=markdown) \n [SA-9 External Information System Services](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sa-9&format=markdown) |
   | Enterprise System and Services Acquisition (ESA) | [ESA-5 Subcontractor Risk Management](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-esa-5&format=markdown) |
   | Security Assessment and Authorization (CA) | [CA-3 System Interconnections](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ca-3&format=markdown) |
   {: caption="Related controls  in IBM Cloud Framework for Financial Services for using only Financial Services Validated services [FSv1.1]" caption-side="top"}
   {: #related-controls-fsv1.1}
   {: tab-title="FSv1.1"}
   {: tab-group="RelatedControls-5"}
   {: class="simple-tab-table"}


1. Set the session inactivity timeout to 15 minutes. For more information, see [Setting the sign-out due to inactivity duration](https://cloud.ibm.com/docs/account?topic=account-iam-work-sessions&format=markdown#sessions-inactivity).

   The following table shows the controls that are most related to this step.

   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Access Control (AC) | [AC-11 Device Lock](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-11&format=markdown) |
   {: caption="Related controls in IBM Cloud Framework for Financial Services for using only session inactivity timeout [FSv2.0]" caption-side="top"}
   {: #related-controls-fsv2.0}
   {: tab-title="FSv2.0"}
   {: tab-group="RelatedControls-6"}
   {: class="simple-tab-table"}


   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Access Control (AC) | [AC-11 Session Lock](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-11&format=markdown) |
   {: caption="Related controls in IBM Cloud Framework for Financial Services for using only session inactivity timeout [FSv1.1]" caption-side="top"}
   {: #related-controls-fsv1.1}
   {: tab-title="FSv1.1"}
   {: tab-group="RelatedControls-6"}
   {: class="simple-tab-table"}


1. [Update company profile details](https://cloud.ibm.com/docs/account?topic=account-contact-info&format=markdown).

   The following table shows the controls that are most related to this step.

   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Configuration Management (CM) | [CM-8 (4) System Component Inventory &#124; Accountability Information](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-cm-8.4&format=markdown) |
   {: caption="Related IBM Cloud Framework for Financial Services controls for updating company profile details [FSv2.0]" caption-side="top"}
   {: #related-controls-fsv2.0}
   {: tab-title="FSv2.0"}
   {: tab-group="RelatedControls-7"}
   {: class="simple-tab-table"}


   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | Configuration Management (CM) | [CM-8 (4) Information System Component Inventory &#124; Accountability Information](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-cm-8.4&format=markdown) |
   {: caption="Related IBM Cloud Framework for Financial Services controls for updating company profile details [FSv1.1]" caption-side="top"}
   {: #related-controls-fsv1.1}
   {: tab-title="FSv1.1"}
   {: tab-group="RelatedControls-7"}
   {: class="simple-tab-table"}


1. [Set email preferences for notifications](https://cloud.ibm.com/docs/account?topic=account-email-prefs&format=markdown). You can receive email notifications about IBM Cloud platform-related items, such as announcements, critical events, security notices, billing and usage, and ordering.

   The following table shows the controls that are most related to this step.

   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | System and Information Integrity (SI) |  [SI-2 Flaw Remediation](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-si-2&format=markdown) \n [SI-5 Security Alerts, Advisories, and Directives](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-si-5&format=markdown) |
   {: caption="Related IBM Cloud Framework for Financial Services controls for configuring notifications [FSv2.0]" caption-side="top"}
   {: #related-controls-fsv2.0}
   {: tab-title="FSv2.0"}
   {: tab-group="RelatedControls-8"}
   {: class="simple-tab-table"}


   | Family              | Control                                           |
   |---------------------|---------------------------------------------------|
   | System and Information Integrity (SI) |  [SI-2 Flaw Remediation](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-si-2&format=markdown) \n [SI-5 Security Alerts & Advisories](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-si-5&format=markdown) |
   {: caption="Related IBM Cloud Framework for Financial Services controls for configuring notifications [FSv1.1]" caption-side="top"}
   {: #related-controls-fsv1.1}
   {: tab-title="FSv1.1"}
   {: tab-group="RelatedControls-8"}
   {: class="simple-tab-table"}


1. Choose a support plan. For more information, see [Basic, Advanced, and Premium Support plans](https://cloud.ibm.com/docs/get-support?topic=get-support-support-plans&format=markdown).

## Next steps
{: #next-steps}

* [Organizing your IBM Cloud accounts and resources](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-shared-account-organization&format=markdown)