EvidenceSheet

IDM-02 Granting and change of user accounts and access rights

Operate defined procedures for issuing and amending accounts and entitlements for internal staff, external staff and automated system components, so that every grant or change demonstrably conforms to the approved role a

4
artefacts
3
held by a system
1
at each review
easy
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Provisioning workflow definition covering joiners, movers and technical accounts · Identity provider / directory
  • Sample of completed access request tickets showing requested role and recorded approver · Identity provider / directory
  • Export of entitlements granted during the period reconciled against approved requests · Identity provider / directory

periodic reviewEvidence produced at each review

  • Screenshot of the request form fields that force selection from the defined role catalogue · Identity provider / directory

governing documentDocuments that govern the control

none for this control

First move

Automate the pull from your Identity provider / directory. Scheduled export of users, roles and MFA state from the directory; access-review completion pulled from the IdP, not a spreadsheet.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

IDM-01 Policy for user accounts and access rights · IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins