EvidenceSheet

5.18 Access rights

Requires access rights to information and other associated assets to be provisioned, reviewed, modified and removed in accordance with the organisation's topic specific policy and rules on access control.

5
artefacts
1
held by a system
4
at each review
hard
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Provisioning records showing the authorisation behind each access grant, tied to the access control rules · Identity provider / directory

periodic reviewEvidence produced at each review

  • Modification records where access changed after a role change, showing removal of the previous entitlements · Identity provider / directory
  • Removal records on termination, with the date of removal against the date of departure · Identity provider / directory
  • Access review evidence per system, showing who reviewed, what they saw, what was revoked and when the revocation took effect · Identity provider / directory
  • Evidence the reviewer had enough information to judge, such as entitlement descriptions rather than raw group names · Identity provider / directory

governing documentDocuments that govern the control

none for this control

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Identity provider / directory on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

5.17 Authentication information · 5.19 Information security in supplier relationships