Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

User Access Review Pack — Guide

User Access Review Pack

A manager receives a list of 200 accounts, half of them named after roles nobody recognises. The deadline is Friday, so everything is approved in four minutes. Nobody checks the few removals requested. This pack helps you run an access review that produces genuine decisions, not bulk approvals under time pressure.

Is this for you?

This pack is for you if:

  • reviewers approve whole lists without opening them;
  • you cannot show that a removal was actually made;
  • leavers and administrator accounts turn up in audits.

How often

AccessEveryWhy
Privileged and administrator access, all systems3 monthsThe access that can do most harm, and changes most often
Systems supporting a critical service6 monthsRegulated minimum for these systems
All other in-scope systems12 monthsRegulated minimum for all other systems

The regulated minimums: six months for systems supporting a DORA critical or important function or cardholder data in PCI DSS scope; a year for the rest.

Four decisions, and no default

Every entry gets one of four decisions (AR-05): Keep, Modify, Revoke or Cannot decide. Line managers judge need; system owners judge permissions.

“Cannot decide” beats a guess. A reviewer who does not know the person or the permission passes it to the system owner within two working days. It never becomes Keep by default, and neither does silence. Nobody reviews their own access (AR-04).

What a rubber stamp looks like

Before closing a campaign, check for the signs (AR-09):

  • a reviewer keeps every entry of a list longer than 25 in one sitting;
  • decisions average under five seconds each;
  • leavers, or accounts with no sign-in for 90 days, are marked Keep;
  • privileged or generic accounts are kept without a named owner.

The evidence auditors test

Auditors pick a Revoke and ask to see that the access is gone. The proof is a fresh extract, taken after the change, that no longer shows it (AR-07). Privileged access must go within one working day of the decision, other access within five.

Start with these three

  1. Access Review Scope & System Inventory — every system, its owner and how to extract who has access.
  2. Access Review Methodology — the twelve rules, the frequencies and the four decisions.
  3. Access Review Campaign Workbook — one campaign’s extracts and decisions, system by system.

Your first campaign

Day 0 is the extract date; list systems and owners before it.

Working daysWhat to doYou’re done when
0–1Take every extract on one stated date; check it is complete.Each list shows names, roles, permissions and last sign-in.
2Assign reviewers and launch.Nobody has their own access to review.
3–10Reviewers decide; chase the silent.Every entry has a decision by day 10.
11–20Remove, confirm against a fresh extract, check quality and close.Removals are confirmed; the evidence file is signed off.

Four numbers to report

NumberTarget
Systems reviewed within their frequencyAll
Removals confirmed within their window95% or more
Leaver, dormant and orphan accounts foundFalling campaign on campaign
Process weaknesses openNone past their date

Report risk removed and weaknesses found, not just percentage completed (AR-12). A process weakness, such as leavers never removed, goes to that process’s owner with a fix and a date (AR-11). Privileged access findings belong in the risk register. A segregation-of-duties conflict is handled with the exceptions pack’s conflict matrix.

Everything in the pack

DocumentWhat it doesFormat
Access Review MethodologyThe rules management approvesWord
Access Review Campaign Operating ProcedureFrom extract to sign-offWord
Access Review Scope & System InventorySystems, owners and frequenciesExcel
Reviewer Instruction Pack & Campaign CommunicationsWhat reviewers are told, and whenWord
Access Review Campaign WorkbookEvery entry and its decisionExcel
Access Review Findings & Revocation TrackerRemovals, confirmations and findingsExcel
Access Review Evidence & Audit File ChecklistWhat the evidence file must holdExcel
Access Review Outcome Report TemplateResults for managementWord

Adapting it

  • Small organisation: start with administrator access and your one or two critical systems.
  • Regulated entity: NIS2 Article 21(2)(i) names access control policies. DORA Article 9(4)(c) limits access to what approved functions require; RTS Article 21(e) sets review at least every six months for systems supporting critical or important functions and yearly for others. PCI DSS Requirement 7.2.4 asks for a six-monthly review of user accounts in scope, third-party accounts included.
  • Access managed by an IT provider or SaaS vendor: you still decide; they make the change. Agree extracts and removal times, then confirm their removals against a fresh extract.

Where it maps

  • ISO/IEC 27001:2022 — Annex A 5.18 and 8.2.
  • NIST CSF 2.0 — PR.AA-05.
  • NIS2 — Article 21(2)(i).
  • DORA — Article 9(4)(c); Delegated Regulation (EU) 2024/1774, Article 21(e).
  • PCI DSS v4.0.1 — Requirement 7.2.4.