GS-6 Define and implement identity and privileged access strategy
Define and implement an identity and privileged access strategy with documented guidance, policy and standards for the identity system, authentication strength, privileged access and entitlement lifecycle.
4
artefacts
1
held by a system
0
at each review
moderate
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Joiner, mover and leaver process aligned to the strategy · Identity provider / directory
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Identity and privileged access strategy document · Policy repository / GRC workspace
- Authentication standard including strength requirements · Policy repository / GRC workspace
- Privileged access model and its governing policy · Policy repository / GRC workspace
First move
Start with the 1 of 4 artefacts that already live in a system (Identity provider / directory); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- strategy covers employees only, omitting workload and partner identities
- privileged access approach differs per platform with no unifying policy
- strategy silent on entitlement review cadence
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetGS-5 Define and implement security posture management strategy · GS-7 Define and implement logging, threat detection and incident response strategy