7.2.3 Required privileges are approved by authorized personnel
Required privileges are approved by authorized personnel.
5
artefacts
1
held by a system
2
at each review
hard
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Records showing an approval was refused or reduced, demonstrating the process is real · Identity provider / directory
periodic reviewEvidence produced at each review
- Evidence that the approval specifies the privileges granted, so assignment can be checked against it · Identity provider / directory
- Evidence no privileges exist without a corresponding documented approval · Identity provider / directory
governing documentDocuments that govern the control
- Policies and procedures defining the approval process for privileges and who is authorised to approve · Policy repository / GRC workspace
- Documented approvals for a sample of user IDs, matched against the privileges actually assigned · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Identity provider / directory on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Approvals held as email threads that do not state which privileges were approved
- Privileges assigned first and approved retrospectively, or never
- Approver is the same person as the requester for administrative accounts
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet7.2.2 Access is assigned to users, including privileged users, based on: • Job classification and function. • Least privileges necessary to perform job responsibilities · 7.2.4 All user accounts and related access privileges, including third-party/vendor accounts, are reviewed as follows: • At least once every six months. • To ensure user accounts and access remain appropriate based on job function.