7.2.5.1 App and system account review cadence
Application and system account access is reviewed at a frequency defined in the entity's targeted risk analysis (TRA).
system holds itEvidence a system already holds
- Audit log of permission changes · Identity provider / directory
periodic reviewEvidence produced at each review
- TRA document supporting chosen review frequency · Document repository
- Review schedule and completed review reports · Document repository
- Tickets remediating findings from reviews · Ticketing / ITSM
- Sign-off from account owner per review · Identity provider / directory
governing documentDocuments that govern the control
none for this control
First move
Common gaps auditors find
- No TRA on file
- Review frequency too low for risk
- Findings open beyond SLA
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet7.2.5 All application and system accounts and related access privileges are assigned and managed as follows: • Based on the least privileges necessary for the operability of the system or application. • Access is limited · 7.2.6 All user access to query repositories of stored cardholder data is restricted as follows: • Via applications or other programmatic methods, with access and allowed actions based on user roles and least privileges. •