5.18 Access rights
Requires access rights to information and other associated assets to be provisioned, reviewed, modified and removed in accordance with the organisation's topic specific policy and rules on access control.
5
artefacts
1
held by a system
4
at each review
hard
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Provisioning records showing the authorisation behind each access grant, tied to the access control rules · Identity provider / directory
periodic reviewEvidence produced at each review
- Modification records where access changed after a role change, showing removal of the previous entitlements · Identity provider / directory
- Removal records on termination, with the date of removal against the date of departure · Identity provider / directory
- Access review evidence per system, showing who reviewed, what they saw, what was revoked and when the revocation took effect · Identity provider / directory
- Evidence the reviewer had enough information to judge, such as entitlement descriptions rather than raw group names · Identity provider / directory
governing documentDocuments that govern the control
none for this control
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Identity provider / directory on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Role change results in access being added while the previous access is never withdrawn, accumulating entitlement
- Access reviews certified wholesale with everything approved and nothing revoked, which is the single most common finding
- Review outcomes recorded but revocations never actioned or never verified as actioned
- Privileged and third party access excluded from review, or reviewed by the team that holds it
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet5.17 Authentication information · 5.19 Information security in supplier relationships