IDM-02 Granting and change of user accounts and access rights
Operate defined procedures for issuing and amending accounts and entitlements for internal staff, external staff and automated system components, so that every grant or change demonstrably conforms to the approved role a
4
artefacts
3
held by a system
1
at each review
easy
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Provisioning workflow definition covering joiners, movers and technical accounts · Identity provider / directory
- Sample of completed access request tickets showing requested role and recorded approver · Identity provider / directory
- Export of entitlements granted during the period reconciled against approved requests · Identity provider / directory
periodic reviewEvidence produced at each review
- Screenshot of the request form fields that force selection from the defined role catalogue · Identity provider / directory
governing documentDocuments that govern the control
none for this control
First move
Automate the pull from your Identity provider / directory. Scheduled export of users, roles and MFA state from the directory; access-review completion pulled from the IdP, not a spreadsheet.
Common gaps auditors find
- Entitlements set directly in the target system, bypassing the request workflow entirely
- Requester and approver are the same person on a portion of sampled requests
- Roles entered as free text instead of catalogue values, producing entitlements outside the concept
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetIDM-01 Policy for user accounts and access rights · IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins