Access Review Campaign Operating Procedure
Runs a campaign end to end: extract, distribute, chase, decide, revoke, verify and evidence.
Available soon
- Format
- Word
- Size
- 60 KB
- Length
- 18 pages
- Version
- 1.0
- Updated
What's inside
- Purpose
- Scope
- Roles
- Triggers and inputs
- Procedure steps
- Decision points
- Timing targets
- Escalation
- Worked example — campaign UAR-2026-Q3
- Outputs and records produced
- Evidence retained
- Related documents
- Adapting this template
- Framework references
- Definitions
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
Purpose
This procedure sets out how [[Organisation Name]] runs one access review campaign, from taking the extracts to closing the evidence file. It is the working routine behind the Access Review Methodology: the methodology states the rules (AR-01 to AR-12), the frequencies, the four decisions and the removal windows; this procedure says who does what, on which working day, and what record each step leaves.
A campaign is finished when every entry has a decision, every Revoke and Modify has been confirmed against a fresh extract, the quality check is done, and the findings have gone to the people who can fix their causes. It is not finished when the lists come back.
Scope
This procedure applies to:
- every system in the Access Review Scope & System Inventory that is due for review under its frequency, and every account on it: personal, privileged, generic, service and third-party;
- scheduled campaigns and out-of-cycle reviews (after a restructure, an incident involving misuse of access or a change of system owner);
- everyone with a role in the table below, including suppliers that take extracts or make changes for us.
It does not cover granting new access ([[your access control procedure]]), the leaver process itself ([[your joiner, mover and leaver procedure]]), or approving a segregation-of-duties conflict that cannot be separated (the Security Exception & Waiver Standard in the Security Exception, Waiver & Segregation of Duties pack). It hands over to each at the step named.
Roles
Role | What they do in this procedure |
|---|---|
Campaign coordinator [[e.g. Information Security Manager]] | Plans the campaign; checks each extract is complete; assigns reviewers; sends lists; chases; raises change tickets; compares the fresh extract; raises findings; assembles the evidence file. |
System owner [[the manager accountable for the system]] | Confirms scope and extract method; decides permissions, and every privileged, generic, service and third-party account; decides Cannot decide and unanswered entries; signs off the system's results. |
Line manager [[each person's manager]] | Decides for each of their people: does this person still need this access for their current job? |
System administrator [[IT operations, or the supplier's support team]] | Takes the extracts on the stated date; carries out removals within the windows; takes the fresh extract. |
Head of Information Security [[e.g. Head of Information Security]] | Reviews every privileged account a second time; runs the quality check; decides what is still undecided; signs the campaign closed; reports the measures. |
HR [[for joiner, mover and leaver data]] | Supplies the list of current staff and contractors, leavers and movers; owns the fix when leavers are not being removed. |
Guidance — delete before approval
In a small organisation the campaign coordinator and the Head of Information Security may be one person, and the system administrator may be the IT manager. That is acceptable, with one limit: nobody reviews or signs off their own access (AR-04). Have [[another executive or an external adviser]] review the administrator accounts of whoever runs IT.
Triggers and inputs
When this procedure runs
Event | What starts |
|---|---|
A system reaches its review frequency (3 months, 6 months, 12 months, by scope; AR-02) | A scheduled campaign, usually one per quarter covering every system due |
A restructure, merger, or a change of system owner | An out-of-cycle review of the systems affected |
An incident involving misuse of access | An out-of-cycle review of the systems involved, starting at step 1 |
An auditor or regulator asks for evidence of review | Nothing new: step 19's evidence file answers it |
Inputs
Input | Where it comes from | Used at |
|---|---|---|
Systems due, their owners, scopes and extract methods | Access Review Scope & System Inventory | Step 1 |
Current staff and contractors, leavers and movers | HR | Steps 2, 4 |
Access extracts | System administrator; for hosted systems, the supplier | Steps 3, 4 |
Reviewer instructions and campaign messages | Reviewer Instruction Pack & Campaign Communications | Steps 6, 7 |
The campaign workbook: lists, decisions, status | Access Review Campaign Workbook | Steps 5 to 11 |
Conflicts to check | Segregation of Duties Conflict Matrix (Security Exception, Waiver & Segregation of Duties pack) | Step 11 |
Open findings and weaknesses from the last campaign | Access Review Findings & Revocation Tracker | Steps 1, 16 |
Procedure steps
Days are working days from the extract date (day 0): Monday to Friday, excluding [[public holidays]]. The timetable is summarised under Timing targets. A campaign that starts late keeps the same gaps between steps.
Stage 1 — Prepare and extract (days 0 to 1)
Step | What happens | Who | When | Output |
|---|---|---|---|---|
1 | List the systems due this campaign from the Access Review Scope & System Inventory, with owner, scope and extract method (AR-01, AR-02). Add any open finding from the last campaign that this one must check. Confirm the extract date with each system owner, and for a hosted system, raise the supplier's ticket early enough for the extract to be dated day 0. | Campaign coordinator | [[10]] working days before day 0 | Campaign scope list |
2 | Supply the current list of staff and contractors (name, job title, manager, department) and every leaver and mover since the last campaign for these systems. | HR | By day 0 | People list |
3 | Take the extract of each system on day 0: every account, account type, role or group, permissions and last sign-in (AR-03). Save it unchanged, with its date, to the evidence location. | System administrator | day 0 | Dated extracts |
4 | Check each extract is complete: its account count matches the system's own count; every column is filled; privileged groups are included; service and third-party accounts are present. Match it to the people list and mark leavers, movers, accounts with no sign-in for [[90]] days and accounts with no owner, so reviewers see them. | Campaign coordinator | day 1 | Checked extract, with flags |
Guidance — delete before approval
An extract that fails the completeness check is taken again, not reviewed. A system whose extract cannot be completed this campaign is left out, and that is a finding against AR-01 and AR-03, reported with the campaign.
Stage 2 — Distribute (day 2)
Step | What happens | Who | When | Output |
|---|---|---|---|---|
5 | Assign each entry to its reviewer: personal accounts to the line manager; permissions and every privileged, generic, service and third-party account to the system owner (AR-06). Check independence: nobody gets their own access, or the access of someone who reviews theirs (AR-04); reassign any that break it. | Campaign coordinator | day 2 | Reviewer assignments |
6 | Send each reviewer their list with the reviewer instructions from the Reviewer Instruction Pack & Campaign Communications, the four decisions, and the deadline: day 10. Send the privileged accounts to information security at the same time for the second review. | Campaign coordinator | day 2 | Lists sent; send log |
Stage 3 — Chase (days 3 to 10)
Step | What happens | Who | When | Output |
|---|---|---|---|---|
7 | Track returns daily. Send the first reminder to every reviewer with entries still open. | Campaign coordinator | day 5 | Reminder log |
8 | Send the second reminder, copied to the reviewer's own manager, naming the deadline and what happens if it is missed. | Campaign coordinator | day 8 | Reminder log |
Stage 4 — Decide (by day 10)
Step | What happens | Who | When | Output |
|---|---|---|---|---|
9 | Decide every entry: Keep, Modify, Revoke or Cannot decide (AR-05). Give a reason for Modify (which permission) and for Revoke. Cannot decide is for an entry the reviewer cannot judge, not for an entry they have not looked at. | Line manager; System owner | By day 10 | Decisions in the workbook |
10 | Close decisions on day 10. Send every Cannot decide entry, and every entry with no answer, to the system owner, who decides it within [[2]] working days. No entry is kept because nobody answered (AR-05). Privileged entries cannot wait: the system owner is already their reviewer (AR-06), so they are decided by day 10. | Campaign coordinator; System owner | day 10 to day 12 | Every entry decided |
11 | Review every privileged decision a second time (AR-06). Check the decisions against the Segregation of Duties Conflict Matrix for the systems it covers: a conflict is raised as a finding (step 14) and decided Modify where the duties can be separated. | Head of Information Security | By day 10 | Second review; conflicts found |
The decisions, as the methodology defines them:
Decision | Meaning |
|---|---|
Keep | Access is needed and the permissions are right. |
Modify | Access is needed but some permissions are not: remove the excess. |
Revoke | Access is not needed: remove it. |
Cannot decide | The reviewer does not know the person or the permission: it goes to the system owner within [[2]] working days, never to Keep by default. |
Stage 5 — Revoke (days 10 to 15)
Step | What happens | Who | When | Output |
|---|---|---|---|---|
12 | Raise one change ticket per system listing every Revoke and Modify, marked privileged or standard, with the removal due date. For a hosted system, raise it with the supplier. | Campaign coordinator | day 10 | Change tickets |
13 | Remove the access (AR-07). Privileged and administrator access within 1 working day of the decision date; all other access within 5 working days. Tell the campaign coordinator of anything that cannot be done in time, before the window ends. | System administrator | Privileged by day 11; standard by day 15 | Tickets completed |
Stage 6 — Findings and verification (days 10 to 18)
Step | What happens | Who | When | Output |
|---|---|---|---|---|
14 | Raise a finding for every leaver, dormant account, orphan account and segregation-of-duties conflict found (AR-08), in the Access Review Findings & Revocation Tracker, with the system, the account and how long it existed. A conflict that cannot be separated goes to the exception process: recorded in the Security Exception Register with a compensating control. | Campaign coordinator | From day 10; all by day 18 | Findings |
15 | Take a fresh extract of each system and compare it with the decisions. Each Revoke and Modify is confirmed only if the access has gone from the fresh extract, not because the ticket is closed. Anything still present is removed again the same day, escalated and checked again. Record for each removal the date the access was removed and the date it was confirmed. A removal is late when the access is removed after its window, which counts from the decision deadline (or from the quality check, for a decision the quality check changed); every removal is then confirmed against a fresh extract. | System administrator; Campaign coordinator | day 16 | Confirmation record; late removals |
Stage 7 — Quality check, evidence and close (days 17 to 20)
Step | What happens | Who | When | Output |
|---|---|---|---|---|
16 | Run the quality check on every reviewer's list (AR-09). Where a signal shows, have the list re-reviewed by the system owner or check a sample of [[10]] entries, and change any wrong decision (which then runs steps 12 to 15 again). The campaign does not close while a signal is unresolved. | Head of Information Security | day 17 | Quality check record |
17 | Group findings with the same cause into process weaknesses (PW-nn) and send each to the owner of that process with a fix and a date (AR-11). Update weaknesses still open from the last campaign. | Campaign coordinator; Head of Information Security | day 18 | Process weaknesses |
18 | Complete the evidence file, using the Access Review Evidence & Audit File Checklist: scope, extracts, assignments, decisions, tickets, fresh extracts, findings, quality check (AR-10). | Campaign coordinator | By day 20 | Evidence file |
19 | Each system owner signs off their system's results; the Head of Information Security signs the campaign closed. | System owner; Head of Information Security | day 20 | Signed close |
20 | Report the campaign with ARM-01, ARM-02, ARM-03, ARM-04 in the Access Review Outcome Report Template, as risk removed and weaknesses found (AR-12). | Head of Information Security | Within [[5]] working days of day 20 | Campaign report |
The quality signals checked at step 16:
Signal | Action |
|---|---|
A reviewer keeps 100% of a large list (more than [[25]] entries) in one sitting | Re-review by the system owner, or a sample of [[10]] entries checked |
Decisions made faster than [[5]] seconds each on average | Sample of [[10]] entries checked; if any is wrong, the whole list is re-reviewed |
Leavers or dormant accounts (no sign-in for [[90]] days) marked Keep | Changed to Revoke by the system owner; the reviewer's other decisions sampled |
Privileged or generic accounts marked Keep without a named owner | Changed to Cannot decide until the system owner names an owner |
Decision points
Decision | Who decides | Rule | Recorded in |
|---|---|---|---|
Is the extract complete enough to review? | Campaign coordinator | Counts and columns checked (AR-03) | Access Review Campaign Workbook |
Who reviews this entry? | Campaign coordinator | Reviewer by account type; independence (AR-04, AR-06) | Access Review Campaign Workbook |
Keep, Modify, Revoke or Cannot decide? | Line manager; System owner | The four decisions and the questions in the methodology (AR-05) | Access Review Campaign Workbook |
A Cannot decide or unanswered entry | System owner | Within [[2]] working days; never Keep by default | Access Review Campaign Workbook |
Can a conflict be separated? | System owner | Modify if yes; exception under the Security Exception & Waiver Standard if not | Access Review Findings & Revocation Tracker; Security Exception Register |
Is a removal confirmed? | Campaign coordinator | Gone from the fresh extract (AR-07) | Access Review Findings & Revocation Tracker |
Can the campaign close? | Head of Information Security | Every entry decided, removals confirmed, quality signals resolved (AR-09, AR-10) | Access Review Evidence & Audit File Checklist |
Timing targets
The campaign timetable, in working days from the extract date. The day numbers are this template's defaults; a larger campaign may stretch the review phase, but keep the removal windows, which the methodology sets.
Phase | Days | EXAMPLE dates, UAR-2026-Q3 |
|---|---|---|
Extract and check completeness | Days 0 to 1 | 1 September 2026 to 2 September 2026 |
Assign reviewers and launch | Day 2 | 3 September 2026 |
Review and decide | Days 3 to 10 | 4 September 2026 to 15 September 2026 |
Remove, confirm against a fresh extract, check quality and close | Days 11 to 20 | 16 September 2026 to 29 September 2026 |
Milestone | Day | Basis |
|---|---|---|
Extract taken | Day 0 | AR-03 |
Completeness checked | Day 1 | AR-03 |
Lists sent | Day 2 | AR-04, AR-06 |
First reminder | Day 5 | — |
Second reminder, copied to the reviewer's manager | Day 8 | AR-05 |
Decisions due | Day 10 | AR-05 |
Privileged removals done | Day 11 (1 working day after decisions) | AR-07 |
Cannot decide and unanswered entries decided | Day 12 ([[2]] working days) | AR-05 |
Standard removals done | Day 15 (5 working days after decisions) | AR-07 |
Fresh extract and confirmation | Day 16 | AR-07 |
Quality check | Day 17 | AR-09 |
Findings and process weaknesses sent | Day 18 | AR-08, AR-11 |
Evidence complete; campaign closed | Day 20 | AR-10 |
Campaign report | Within [[5]] working days of day 20 | AR-12 |
Guidance — delete before approval
Removal windows are counted from the decision date (day 10) for every entry, including those the system owner decides later, so late decisions leave less time to remove. That is deliberate: it gives a reason to decide on time. The one exception is a decision the quality check changes (step 16): its window counts from the day of the quality check.
Targets for the measures: ARM-01 Reviews on time: all; ARM-02 Removals confirmed on time: ≥ [[95%]]; ARM-03 Access that should not have existed: falling campaign on campaign; ARM-04 Process weaknesses open: zero past their date.
Escalation
Nothing is kept by default when a reviewer does not answer (AR-05). The ladder for a reviewer who has not decided:
When | What happens | By |
|---|---|---|
day 5 | First reminder to the reviewer | Campaign coordinator |
day 8 | Second reminder, copied to the reviewer's own manager | Campaign coordinator |
day 10 | Open entries go to the system owner, who decides them within [[2]] working days | Campaign coordinator |
day 12 | Anything still undecided goes to the Head of Information Security, who decides it or has the access [[suspended]] until someone does. The reviewer is named in the campaign report | Campaign coordinator; Head of Information Security |
Other escalations | Escalated to | By | Basis |
|---|---|---|---|
Extract not provided or incomplete by day 1 | System owner; then Head of Information Security | Campaign coordinator | AR-01, AR-03 |
A removal that cannot be done within its window | System owner; a supplier's delay also to the manager of that contract | System administrator | AR-07 |
Access still present in the fresh extract | System administrator the same day; then Head of Information Security | Campaign coordinator | AR-07 |
A segregation-of-duties conflict that cannot be separated | The exception process (Security Exception, Waiver & Segregation of Duties pack) | System owner | AR-08 |
A process weakness past its date | Its owner; then executive management in the campaign report (ARM-04) | Head of Information Security | AR-11, AR-12 |
Worked example — campaign UAR-2026-Q3
EXAMPLE, not part of the procedure. The organisation is the one used throughout the pack: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. The campaign covered 5 systems and 495 entries. Replace every date and figure with your own.
Stage | What happened | Result |
|---|---|---|
1 — Prepare and extract (1 September 2026 to 2 September 2026) | SYS-01 ERP (hosted; P06 SUP-004); SYS-02 Warehouse management system; SYS-03 Directory administrator groups; SYS-04 Online ordering admin console; SYS-05 Shared finance drive. Extracts dated 1 September 2026; the ERP report came from the provider (SUP-004) on a ticket raised 5 working days earlier, the lead time in the Access Review Scope & System Inventory. (EXAMPLE) | 5 checked extracts, 495 entries |
2 — Distribute (3 September 2026) | Personal accounts to line managers; permissions and privileged, generic, service and third-party accounts to each system owner; the directory administrator groups (SYS-03) to the Head of IT, with the Head of Information Security giving the second review (AR-06) and reviewing the Head of IT's own membership (AR-04). (EXAMPLE) | Lists sent |
3 — Chase (8 September 2026, 11 September 2026) | Reminders on day 5 and day 8. (EXAMPLE) | Reminder log |
4 — Decide (due 15 September 2026) | 424 Keep, 22 Modify, 47 Revoke, 2 Cannot decide. The 2 Cannot decide entries were on SYS-01, sent to the Chief Financial Officer and decided by 17 September 2026. (EXAMPLE) | 495 of 495 decided |
Segregation of duties | 1 conflict on SYS-01: one user could create or change suppliers and their bank details and approve payments (High in the Segregation of Duties Conflict Matrix). Raised as a finding. Separated by a Modify; no exception: the Chief Financial Officer separated the duties; the change was requested on 15 September 2026, removed on 22 September 2026 (within the standard window) and confirmed on 23 September 2026. (EXAMPLE) | Separated by a Modify |
5 — Revoke (privileged by 16 September 2026, standard by 22 September 2026) | 69 changes: 47 Revoke and 22 Modify. (EXAMPLE) | 69 tickets |
6 — Verify (23 September 2026) | Fresh extracts taken on 23 September 2026 and compared with the decisions. 4 removals were late, because the access was removed after its window: 3 on SYS-01 (ERP): finance administrator role removed from 3 accounts (2 Modify, 1 Revoke). Privileged window ended 16 September 2026; removed 22 September 2026; confirmed 23 September 2026. The ERP provider (P06 SUP-004) acts on a removal ticket in 5 working days; privileged access must go in 1 (PW-02). 1 on SYS-05 (Shared finance drive): a leaver's access to the shared finance drive (Revoke). Standard window ended 22 September 2026; removed 24 September 2026; confirmed 24 September 2026. The access also came through a nested group. The fresh extract showed it still present, so it was removed a second time. A one-off: nested groups are now on the administrator's removal checklist. (EXAMPLE) | 65 of 69 on time |
Findings (AR-08) | 36 accounts that should not have existed: 13 leavers, 20 dormant, 3 orphan; 7 of the leavers on SYS-02. Plus 1 conflict. (EXAMPLE) | 37 findings |
7 — Quality check (24 September 2026) | Every leaver and dormant account had been marked Revoke by its reviewer, so the third signal did not show; the other signals are read from each reviewer's list in the Access Review Campaign Workbook [[record what was found]]. (EXAMPLE) | Quality check record |
Process weaknesses (25 September 2026) | PW-01: Warehouse leavers are not removed from the warehouse system: HR's leaver notice does not reach its owner. Owner HR Director; due 30 November 2026; open. PW-02: The ERP provider takes 5 working days to remove users; our window is 5 for standard access and 1 for privileged. Owner Chief Financial Officer; due 15 December 2026; open. (EXAMPLE) | 2 weaknesses |
Close (29 September 2026) | Evidence file complete; system owners signed; campaign closed by the Head of Information Security. (EXAMPLE) | Closed |
Report (as at 30 September 2026) | ARM-01: 5 of 5. ARM-02: 65 of 69 = 94.2%, below the ≥ [[95%]] target. ARM-03: 36. ARM-04: 2 open, none past its date. (EXAMPLE) | Campaign report |
What it shows: the 4 late removals are not a reviewer's failure. 3 of them come from a supplier whose removal time does not fit the window, which is why PW-02 goes to the Chief Financial Officer, who owns the contract; the fix is in the contract with SUP-004 (Third-Party Security Risk Management pack), not in the next campaign. The one on SYS-05 was caught only because confirmation used a fresh extract, not the ticket.
Outputs and records produced
Output | Produced at step | Held in | Maintained by |
|---|---|---|---|
Campaign scope list | 1 | Access Review Campaign Workbook | Campaign coordinator |
Dated extracts, with completeness check | 3, 4 | [[evidence location]] | System administrator; Campaign coordinator |
Reviewer assignments and send log | 5, 6 | Access Review Campaign Workbook | Campaign coordinator |
Decisions, with reviewer, date and reason | 9 to 11 | Access Review Campaign Workbook | Campaign coordinator |
Change tickets | 12, 13 | [[ticketing system]] | System administrator |
Findings, confirmations and late removals | 14, 15 | Access Review Findings & Revocation Tracker | Campaign coordinator |
Quality check record | 16 | Access Review Evidence & Audit File Checklist | Head of Information Security |
Process weaknesses | 17 | Access Review Findings & Revocation Tracker | Head of Information Security |
Evidence file and sign-off | 18, 19 | Access Review Evidence & Audit File Checklist | Campaign coordinator |
Campaign report | 20 | Access Review Outcome Report Template | Head of Information Security |
Evidence retained
Evidence | Shows | Minimum retention |
|---|---|---|
Extracts as taken, and the fresh extracts | What access existed, and that removals happened (AR-03, AR-07) | [[3 years]] |
Decisions with reviewer, date and reason | Every entry decided by the right person (AR-04 to AR-06) | [[3 years]] |
Reminders and escalations | Nothing kept by default (AR-05) | [[3 years]] |
Change tickets and confirmations | Removals within their windows (AR-07) | [[3 years]] |
Findings, process weaknesses and their closure | AR-08, AR-11 | [[3 years after closure]] |
Quality check and sign-off | AR-09, AR-10 | [[3 years]] |
Campaign reports | AR-12 | [[5 years]] |
Guidance — delete before approval
An auditor typically picks one system and one campaign and asks for the extract, the decisions, a few removal tickets with the fresh extract that confirms them, and the sign-off. Test this yourself after each campaign on one system.
Related documents
Document | Relationship |
|---|---|
Access Review Methodology | The rules this procedure runs (AR-01 to AR-12), the frequencies, decisions and removal windows |
Access Review Scope & System Inventory | The systems due, their owners and extract methods (step 1) |
Reviewer Instruction Pack & Campaign Communications | What reviewers are sent and told (steps 6 to 8) |
Access Review Campaign Workbook | Lists, decisions and status (steps 5 to 11) |
Access Review Findings & Revocation Tracker | Removals, findings and weaknesses to closure (steps 14, 15, 17) |
Access Review Evidence & Audit File Checklist | The evidence file (step 18) |
Access Review Outcome Report Template | The campaign report (step 20) |
Segregation of Duties Conflict Matrix; Security Exception & Waiver Standard | Conflicts checked at step 11, and the exception route (Security Exception, Waiver & Segregation of Duties pack) |
Adapting this template
Guidance — delete before approval
Small organisation: one campaign a quarter covering whatever is due is enough, run from a spreadsheet and a shared mailbox. Keep the dated extract, the four decisions, the fresh-extract confirmation and the sign-off: they are what an auditor tests. The day 20 close can shrink for a handful of systems; the removal windows cannot.
Regulated entity (DORA, PCI DSS): a DORA financial entity reviews access to systems supporting critical or important functions at least every six months and others at least yearly, with clear roles for granting, reviewing and revoking access (Delegated Regulation (EU) 2024/1774 Article 21(e)); limits access to what approved functions need (Regulation (EU) 2022/2554 Article 9(4)(c)). A PCI DSS entity reviews user accounts, including third-party accounts, at least every six months (7.2.4). Schedule campaigns so no system passes its frequency, and keep the evidence file per system.
IT run by a service provider: the provider takes extracts (step 3) and makes removals (step 13), but the campaign coordinator, the reviewers and the decisions stay with you. Put the extract date, format and the removal times (1 working day privileged, 5 standard) into the contract, and confirm every removal against your own fresh extract, not the provider's ticket.
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; PCI DSS v4.0.1.
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Annex A 5.18 — Access rights | Whole procedure: access rights reviewed, and changes made and confirmed |
ISO/IEC 27001:2022 | Annex A 8.2 — Privileged access rights | Privileged accounts reviewed by the system owner and a second time by information security (steps 5, 11); 1-working-day removal |
ISO/IEC 27001:2022 | Clause 7.5 — Documented information | Evidence file and records (steps 18, 19; Evidence retained) |
NIST CSF 2.0 | PR.AA-05 — “Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties” | Stages 4 to 6: permissions reviewed, and removed where not needed |
DORA — Delegated Regulation (EU) 2024/1774 | Article 21(e) — account management: roles for granting, reviewing and revoking access; privileged access on a need-to-use basis; removal without undue delay; review at least every six months for systems supporting critical or important functions and at least yearly for others | Roles for reviewing and revoking; timetable; regulated-entity tailoring |
PCI DSS v4.0.1 | Requirement 7.2.4 — user accounts and their access privileges, including third-party accounts, reviewed at least every six months | Campaign covering user and third-party accounts; regulated-entity tailoring |
DORA — Regulation (EU) 2022/2554 | Article 9(4)(c) — policies that limit access to information and ICT assets to what is required for legitimate and approved functions, with controls that ensure sound administration of access rights | Decisions limit access to what the job needs |
Definitions
Term | Meaning in this procedure |
|---|---|
Campaign | One round of review across the systems due, with one extract date (day 0), one decision date and one close date. |
Cannot decide | The decision for an entry the reviewer cannot judge; it goes to the system owner. |
Day n | The nth working day after the extract date; the extract date is day 0. |
Extract | The list of every account on a system, with names, roles, permissions and last sign-in, taken on a stated date. |
Fresh extract | A new extract taken after the removal windows, to confirm removals (AR-07). |
Finding | Access that should not have existed, or a conflict, recorded with its cause (AR-08). |
Late removal | A Revoke or Modify whose access was removed after its removal window. Every removal is then confirmed against a fresh extract. |
Process weakness | A cause behind several findings, sent to the owner of the process (AR-11). |
Removal window | 1 working day for privileged access, 5 working days for other access, from the decision date. |
Working day | Monday to Friday, excluding [[public holidays where you are]]. |