6.6.4 System and application access control
System and application access control must restrict access to information, provide secure log on, manage passwords, constrain privileged utilities and protect source code, and where the customer requires it the organizat
5
artefacts
3
held by a system
0
at each review
easy
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Access restriction configuration for applications holding personal data · Identity provider / directory
- Secure log on mechanisms, including any capability offered to customers for accounts they control · Identity provider / directory
- Record of customer requirements for log on capability and how they were met · Identity provider / directory
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Password management and privileged utility controls · Policy repository / GRC workspace
- Source code access controls · Policy repository / GRC workspace
First move
Automate the pull from your Identity provider / directory. Scheduled export of users, roles and MFA state from the directory; access-review completion pulled from the IdP, not a spreadsheet.
Common gaps auditors find
- Application level restriction absent, so any authenticated user reaches every record
- Customer facing accounts left on weaker authentication than internal ones
- Privileged utilities available to operators who need no such access to personal data
- Customer requirement for secure log on captured in a sales document and never implemented
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet