Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Access Review Campaign Operating Procedure

Runs a campaign end to end: extract, distribute, chase, decide, revoke, verify and evidence.

Available soon

Format
Word
Size
60 KB
Length
18 pages
Version
1.0
Updated

What's inside

  • Purpose
  • Scope
  • Roles
  • Triggers and inputs
  • Procedure steps
  • Decision points
  • Timing targets
  • Escalation
  • Worked example — campaign UAR-2026-Q3
  • Outputs and records produced
  • Evidence retained
  • Related documents
  • Adapting this template
  • Framework references
  • Definitions

Preview

The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.

Purpose

This procedure sets out how [[Organisation Name]] runs one access review campaign, from taking the extracts to closing the evidence file. It is the working routine behind the Access Review Methodology: the methodology states the rules (AR-01 to AR-12), the frequencies, the four decisions and the removal windows; this procedure says who does what, on which working day, and what record each step leaves.

A campaign is finished when every entry has a decision, every Revoke and Modify has been confirmed against a fresh extract, the quality check is done, and the findings have gone to the people who can fix their causes. It is not finished when the lists come back.

Scope

This procedure applies to:

  • every system in the Access Review Scope & System Inventory that is due for review under its frequency, and every account on it: personal, privileged, generic, service and third-party;
  • scheduled campaigns and out-of-cycle reviews (after a restructure, an incident involving misuse of access or a change of system owner);
  • everyone with a role in the table below, including suppliers that take extracts or make changes for us.

It does not cover granting new access ([[your access control procedure]]), the leaver process itself ([[your joiner, mover and leaver procedure]]), or approving a segregation-of-duties conflict that cannot be separated (the Security Exception & Waiver Standard in the Security Exception, Waiver & Segregation of Duties pack). It hands over to each at the step named.

Roles

Role

What they do in this procedure

Campaign coordinator

[[e.g. Information Security Manager]]

Plans the campaign; checks each extract is complete; assigns reviewers; sends lists; chases; raises change tickets; compares the fresh extract; raises findings; assembles the evidence file.

System owner

[[the manager accountable for the system]]

Confirms scope and extract method; decides permissions, and every privileged, generic, service and third-party account; decides Cannot decide and unanswered entries; signs off the system's results.

Line manager

[[each person's manager]]

Decides for each of their people: does this person still need this access for their current job?

System administrator

[[IT operations, or the supplier's support team]]

Takes the extracts on the stated date; carries out removals within the windows; takes the fresh extract.

Head of Information Security

[[e.g. Head of Information Security]]

Reviews every privileged account a second time; runs the quality check; decides what is still undecided; signs the campaign closed; reports the measures.

HR

[[for joiner, mover and leaver data]]

Supplies the list of current staff and contractors, leavers and movers; owns the fix when leavers are not being removed.

Guidance — delete before approval

In a small organisation the campaign coordinator and the Head of Information Security may be one person, and the system administrator may be the IT manager. That is acceptable, with one limit: nobody reviews or signs off their own access (AR-04). Have [[another executive or an external adviser]] review the administrator accounts of whoever runs IT.

Triggers and inputs

When this procedure runs

Event

What starts

A system reaches its review frequency (3 months, 6 months, 12 months, by scope; AR-02)

A scheduled campaign, usually one per quarter covering every system due

A restructure, merger, or a change of system owner

An out-of-cycle review of the systems affected

An incident involving misuse of access

An out-of-cycle review of the systems involved, starting at step 1

An auditor or regulator asks for evidence of review

Nothing new: step 19's evidence file answers it

Inputs

Input

Where it comes from

Used at

Systems due, their owners, scopes and extract methods

Access Review Scope & System Inventory

Step 1

Current staff and contractors, leavers and movers

HR

Steps 2, 4

Access extracts

System administrator; for hosted systems, the supplier

Steps 3, 4

Reviewer instructions and campaign messages

Reviewer Instruction Pack & Campaign Communications

Steps 6, 7

The campaign workbook: lists, decisions, status

Access Review Campaign Workbook

Steps 5 to 11

Conflicts to check

Segregation of Duties Conflict Matrix (Security Exception, Waiver & Segregation of Duties pack)

Step 11

Open findings and weaknesses from the last campaign

Access Review Findings & Revocation Tracker

Steps 1, 16

Procedure steps

Days are working days from the extract date (day 0): Monday to Friday, excluding [[public holidays]]. The timetable is summarised under Timing targets. A campaign that starts late keeps the same gaps between steps.

Stage 1 — Prepare and extract (days 0 to 1)

Step

What happens

Who

When

Output

1

List the systems due this campaign from the Access Review Scope & System Inventory, with owner, scope and extract method (AR-01, AR-02). Add any open finding from the last campaign that this one must check. Confirm the extract date with each system owner, and for a hosted system, raise the supplier's ticket early enough for the extract to be dated day 0.

Campaign coordinator

[[10]] working days before day 0

Campaign scope list

2

Supply the current list of staff and contractors (name, job title, manager, department) and every leaver and mover since the last campaign for these systems.

HR

By day 0

People list

3

Take the extract of each system on day 0: every account, account type, role or group, permissions and last sign-in (AR-03). Save it unchanged, with its date, to the evidence location.

System administrator

day 0

Dated extracts

4

Check each extract is complete: its account count matches the system's own count; every column is filled; privileged groups are included; service and third-party accounts are present. Match it to the people list and mark leavers, movers, accounts with no sign-in for [[90]] days and accounts with no owner, so reviewers see them.

Campaign coordinator

day 1

Checked extract, with flags

Guidance — delete before approval

An extract that fails the completeness check is taken again, not reviewed. A system whose extract cannot be completed this campaign is left out, and that is a finding against AR-01 and AR-03, reported with the campaign.

Stage 2 — Distribute (day 2)

Step

What happens

Who

When

Output

5

Assign each entry to its reviewer: personal accounts to the line manager; permissions and every privileged, generic, service and third-party account to the system owner (AR-06). Check independence: nobody gets their own access, or the access of someone who reviews theirs (AR-04); reassign any that break it.

Campaign coordinator

day 2

Reviewer assignments

6

Send each reviewer their list with the reviewer instructions from the Reviewer Instruction Pack & Campaign Communications, the four decisions, and the deadline: day 10. Send the privileged accounts to information security at the same time for the second review.

Campaign coordinator

day 2

Lists sent; send log

Stage 3 — Chase (days 3 to 10)

Step

What happens

Who

When

Output

7

Track returns daily. Send the first reminder to every reviewer with entries still open.

Campaign coordinator

day 5

Reminder log

8

Send the second reminder, copied to the reviewer's own manager, naming the deadline and what happens if it is missed.

Campaign coordinator

day 8

Reminder log

Stage 4 — Decide (by day 10)

Step

What happens

Who

When

Output

9

Decide every entry: Keep, Modify, Revoke or Cannot decide (AR-05). Give a reason for Modify (which permission) and for Revoke. Cannot decide is for an entry the reviewer cannot judge, not for an entry they have not looked at.

Line manager; System owner

By day 10

Decisions in the workbook

10

Close decisions on day 10. Send every Cannot decide entry, and every entry with no answer, to the system owner, who decides it within [[2]] working days. No entry is kept because nobody answered (AR-05). Privileged entries cannot wait: the system owner is already their reviewer (AR-06), so they are decided by day 10.

Campaign coordinator; System owner

day 10 to day 12

Every entry decided

11

Review every privileged decision a second time (AR-06). Check the decisions against the Segregation of Duties Conflict Matrix for the systems it covers: a conflict is raised as a finding (step 14) and decided Modify where the duties can be separated.

Head of Information Security

By day 10

Second review; conflicts found

The decisions, as the methodology defines them:

Decision

Meaning

Keep

Access is needed and the permissions are right.

Modify

Access is needed but some permissions are not: remove the excess.

Revoke

Access is not needed: remove it.

Cannot decide

The reviewer does not know the person or the permission: it goes to the system owner within [[2]] working days, never to Keep by default.

Stage 5 — Revoke (days 10 to 15)

Step

What happens

Who

When

Output

12

Raise one change ticket per system listing every Revoke and Modify, marked privileged or standard, with the removal due date. For a hosted system, raise it with the supplier.

Campaign coordinator

day 10

Change tickets

13

Remove the access (AR-07). Privileged and administrator access within 1 working day of the decision date; all other access within 5 working days. Tell the campaign coordinator of anything that cannot be done in time, before the window ends.

System administrator

Privileged by day 11; standard by day 15

Tickets completed

Stage 6 — Findings and verification (days 10 to 18)

Step

What happens

Who

When

Output

14

Raise a finding for every leaver, dormant account, orphan account and segregation-of-duties conflict found (AR-08), in the Access Review Findings & Revocation Tracker, with the system, the account and how long it existed. A conflict that cannot be separated goes to the exception process: recorded in the Security Exception Register with a compensating control.

Campaign coordinator

From day 10; all by day 18

Findings

15

Take a fresh extract of each system and compare it with the decisions. Each Revoke and Modify is confirmed only if the access has gone from the fresh extract, not because the ticket is closed. Anything still present is removed again the same day, escalated and checked again. Record for each removal the date the access was removed and the date it was confirmed. A removal is late when the access is removed after its window, which counts from the decision deadline (or from the quality check, for a decision the quality check changed); every removal is then confirmed against a fresh extract.

System administrator; Campaign coordinator

day 16

Confirmation record; late removals

Stage 7 — Quality check, evidence and close (days 17 to 20)

Step

What happens

Who

When

Output

16

Run the quality check on every reviewer's list (AR-09). Where a signal shows, have the list re-reviewed by the system owner or check a sample of [[10]] entries, and change any wrong decision (which then runs steps 12 to 15 again). The campaign does not close while a signal is unresolved.

Head of Information Security

day 17

Quality check record

17

Group findings with the same cause into process weaknesses (PW-nn) and send each to the owner of that process with a fix and a date (AR-11). Update weaknesses still open from the last campaign.

Campaign coordinator; Head of Information Security

day 18

Process weaknesses

18

Complete the evidence file, using the Access Review Evidence & Audit File Checklist: scope, extracts, assignments, decisions, tickets, fresh extracts, findings, quality check (AR-10).

Campaign coordinator

By day 20

Evidence file

19

Each system owner signs off their system's results; the Head of Information Security signs the campaign closed.

System owner; Head of Information Security

day 20

Signed close

20

Report the campaign with ARM-01, ARM-02, ARM-03, ARM-04 in the Access Review Outcome Report Template, as risk removed and weaknesses found (AR-12).

Head of Information Security

Within [[5]] working days of day 20

Campaign report

The quality signals checked at step 16:

Signal

Action

A reviewer keeps 100% of a large list (more than [[25]] entries) in one sitting

Re-review by the system owner, or a sample of [[10]] entries checked

Decisions made faster than [[5]] seconds each on average

Sample of [[10]] entries checked; if any is wrong, the whole list is re-reviewed

Leavers or dormant accounts (no sign-in for [[90]] days) marked Keep

Changed to Revoke by the system owner; the reviewer's other decisions sampled

Privileged or generic accounts marked Keep without a named owner

Changed to Cannot decide until the system owner names an owner

Decision points

Decision

Who decides

Rule

Recorded in

Is the extract complete enough to review?

Campaign coordinator

Counts and columns checked (AR-03)

Access Review Campaign Workbook

Who reviews this entry?

Campaign coordinator

Reviewer by account type; independence (AR-04, AR-06)

Access Review Campaign Workbook

Keep, Modify, Revoke or Cannot decide?

Line manager; System owner

The four decisions and the questions in the methodology (AR-05)

Access Review Campaign Workbook

A Cannot decide or unanswered entry

System owner

Within [[2]] working days; never Keep by default

Access Review Campaign Workbook

Can a conflict be separated?

System owner

Modify if yes; exception under the Security Exception & Waiver Standard if not

Access Review Findings & Revocation Tracker; Security Exception Register

Is a removal confirmed?

Campaign coordinator

Gone from the fresh extract (AR-07)

Access Review Findings & Revocation Tracker

Can the campaign close?

Head of Information Security

Every entry decided, removals confirmed, quality signals resolved (AR-09, AR-10)

Access Review Evidence & Audit File Checklist

Timing targets

The campaign timetable, in working days from the extract date. The day numbers are this template's defaults; a larger campaign may stretch the review phase, but keep the removal windows, which the methodology sets.

Phase

Days

EXAMPLE dates, UAR-2026-Q3

Extract and check completeness

Days 0 to 1

1 September 2026 to 2 September 2026

Assign reviewers and launch

Day 2

3 September 2026

Review and decide

Days 3 to 10

4 September 2026 to 15 September 2026

Remove, confirm against a fresh extract, check quality and close

Days 11 to 20

16 September 2026 to 29 September 2026

Milestone

Day

Basis

Extract taken

Day 0

AR-03

Completeness checked

Day 1

AR-03

Lists sent

Day 2

AR-04, AR-06

First reminder

Day 5

—

Second reminder, copied to the reviewer's manager

Day 8

AR-05

Decisions due

Day 10

AR-05

Privileged removals done

Day 11 (1 working day after decisions)

AR-07

Cannot decide and unanswered entries decided

Day 12 ([[2]] working days)

AR-05

Standard removals done

Day 15 (5 working days after decisions)

AR-07

Fresh extract and confirmation

Day 16

AR-07

Quality check

Day 17

AR-09

Findings and process weaknesses sent

Day 18

AR-08, AR-11

Evidence complete; campaign closed

Day 20

AR-10

Campaign report

Within [[5]] working days of day 20

AR-12

Guidance — delete before approval

Removal windows are counted from the decision date (day 10) for every entry, including those the system owner decides later, so late decisions leave less time to remove. That is deliberate: it gives a reason to decide on time. The one exception is a decision the quality check changes (step 16): its window counts from the day of the quality check.

Targets for the measures: ARM-01 Reviews on time: all; ARM-02 Removals confirmed on time: ≥ [[95%]]; ARM-03 Access that should not have existed: falling campaign on campaign; ARM-04 Process weaknesses open: zero past their date.

Escalation

Nothing is kept by default when a reviewer does not answer (AR-05). The ladder for a reviewer who has not decided:

When

What happens

By

day 5

First reminder to the reviewer

Campaign coordinator

day 8

Second reminder, copied to the reviewer's own manager

Campaign coordinator

day 10

Open entries go to the system owner, who decides them within [[2]] working days

Campaign coordinator

day 12

Anything still undecided goes to the Head of Information Security, who decides it or has the access [[suspended]] until someone does. The reviewer is named in the campaign report

Campaign coordinator; Head of Information Security

Other escalations

Escalated to

By

Basis

Extract not provided or incomplete by day 1

System owner; then Head of Information Security

Campaign coordinator

AR-01, AR-03

A removal that cannot be done within its window

System owner; a supplier's delay also to the manager of that contract

System administrator

AR-07

Access still present in the fresh extract

System administrator the same day; then Head of Information Security

Campaign coordinator

AR-07

A segregation-of-duties conflict that cannot be separated

The exception process (Security Exception, Waiver & Segregation of Duties pack)

System owner

AR-08

A process weakness past its date

Its owner; then executive management in the campaign report (ARM-04)

Head of Information Security

AR-11, AR-12

Worked example — campaign UAR-2026-Q3

EXAMPLE, not part of the procedure. The organisation is the one used throughout the pack: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. The campaign covered 5 systems and 495 entries. Replace every date and figure with your own.

Stage

What happened

Result

1 — Prepare and extract (1 September 2026 to 2 September 2026)

SYS-01 ERP (hosted; P06 SUP-004); SYS-02 Warehouse management system; SYS-03 Directory administrator groups; SYS-04 Online ordering admin console; SYS-05 Shared finance drive. Extracts dated 1 September 2026; the ERP report came from the provider (SUP-004) on a ticket raised 5 working days earlier, the lead time in the Access Review Scope & System Inventory. (EXAMPLE)

5 checked extracts, 495 entries

2 — Distribute (3 September 2026)

Personal accounts to line managers; permissions and privileged, generic, service and third-party accounts to each system owner; the directory administrator groups (SYS-03) to the Head of IT, with the Head of Information Security giving the second review (AR-06) and reviewing the Head of IT's own membership (AR-04). (EXAMPLE)

Lists sent

3 — Chase (8 September 2026, 11 September 2026)

Reminders on day 5 and day 8. (EXAMPLE)

Reminder log

4 — Decide (due 15 September 2026)

424 Keep, 22 Modify, 47 Revoke, 2 Cannot decide. The 2 Cannot decide entries were on SYS-01, sent to the Chief Financial Officer and decided by 17 September 2026. (EXAMPLE)

495 of 495 decided

Segregation of duties

1 conflict on SYS-01: one user could create or change suppliers and their bank details and approve payments (High in the Segregation of Duties Conflict Matrix). Raised as a finding. Separated by a Modify; no exception: the Chief Financial Officer separated the duties; the change was requested on 15 September 2026, removed on 22 September 2026 (within the standard window) and confirmed on 23 September 2026. (EXAMPLE)

Separated by a Modify

5 — Revoke (privileged by 16 September 2026, standard by 22 September 2026)

69 changes: 47 Revoke and 22 Modify. (EXAMPLE)

69 tickets

6 — Verify (23 September 2026)

Fresh extracts taken on 23 September 2026 and compared with the decisions. 4 removals were late, because the access was removed after its window:

3 on SYS-01 (ERP): finance administrator role removed from 3 accounts (2 Modify, 1 Revoke). Privileged window ended 16 September 2026; removed 22 September 2026; confirmed 23 September 2026. The ERP provider (P06 SUP-004) acts on a removal ticket in 5 working days; privileged access must go in 1 (PW-02).

1 on SYS-05 (Shared finance drive): a leaver's access to the shared finance drive (Revoke). Standard window ended 22 September 2026; removed 24 September 2026; confirmed 24 September 2026. The access also came through a nested group. The fresh extract showed it still present, so it was removed a second time. A one-off: nested groups are now on the administrator's removal checklist.

(EXAMPLE)

65 of 69 on time

Findings (AR-08)

36 accounts that should not have existed: 13 leavers, 20 dormant, 3 orphan; 7 of the leavers on SYS-02. Plus 1 conflict. (EXAMPLE)

37 findings

7 — Quality check (24 September 2026)

Every leaver and dormant account had been marked Revoke by its reviewer, so the third signal did not show; the other signals are read from each reviewer's list in the Access Review Campaign Workbook [[record what was found]]. (EXAMPLE)

Quality check record

Process weaknesses (25 September 2026)

PW-01: Warehouse leavers are not removed from the warehouse system: HR's leaver notice does not reach its owner. Owner HR Director; due 30 November 2026; open.

PW-02: The ERP provider takes 5 working days to remove users; our window is 5 for standard access and 1 for privileged. Owner Chief Financial Officer; due 15 December 2026; open. (EXAMPLE)

2 weaknesses

Close (29 September 2026)

Evidence file complete; system owners signed; campaign closed by the Head of Information Security. (EXAMPLE)

Closed

Report (as at 30 September 2026)

ARM-01: 5 of 5. ARM-02: 65 of 69 = 94.2%, below the ≥ [[95%]] target. ARM-03: 36. ARM-04: 2 open, none past its date. (EXAMPLE)

Campaign report

What it shows: the 4 late removals are not a reviewer's failure. 3 of them come from a supplier whose removal time does not fit the window, which is why PW-02 goes to the Chief Financial Officer, who owns the contract; the fix is in the contract with SUP-004 (Third-Party Security Risk Management pack), not in the next campaign. The one on SYS-05 was caught only because confirmation used a fresh extract, not the ticket.

Outputs and records produced

Output

Produced at step

Held in

Maintained by

Campaign scope list

1

Access Review Campaign Workbook

Campaign coordinator

Dated extracts, with completeness check

3, 4

[[evidence location]]

System administrator; Campaign coordinator

Reviewer assignments and send log

5, 6

Access Review Campaign Workbook

Campaign coordinator

Decisions, with reviewer, date and reason

9 to 11

Access Review Campaign Workbook

Campaign coordinator

Change tickets

12, 13

[[ticketing system]]

System administrator

Findings, confirmations and late removals

14, 15

Access Review Findings & Revocation Tracker

Campaign coordinator

Quality check record

16

Access Review Evidence & Audit File Checklist

Head of Information Security

Process weaknesses

17

Access Review Findings & Revocation Tracker

Head of Information Security

Evidence file and sign-off

18, 19

Access Review Evidence & Audit File Checklist

Campaign coordinator

Campaign report

20

Access Review Outcome Report Template

Head of Information Security

Evidence retained

Evidence

Shows

Minimum retention

Extracts as taken, and the fresh extracts

What access existed, and that removals happened (AR-03, AR-07)

[[3 years]]

Decisions with reviewer, date and reason

Every entry decided by the right person (AR-04 to AR-06)

[[3 years]]

Reminders and escalations

Nothing kept by default (AR-05)

[[3 years]]

Change tickets and confirmations

Removals within their windows (AR-07)

[[3 years]]

Findings, process weaknesses and their closure

AR-08, AR-11

[[3 years after closure]]

Quality check and sign-off

AR-09, AR-10

[[3 years]]

Campaign reports

AR-12

[[5 years]]

Guidance — delete before approval

An auditor typically picks one system and one campaign and asks for the extract, the decisions, a few removal tickets with the fresh extract that confirms them, and the sign-off. Test this yourself after each campaign on one system.

Related documents

Document

Relationship

Access Review Methodology

The rules this procedure runs (AR-01 to AR-12), the frequencies, decisions and removal windows

Access Review Scope & System Inventory

The systems due, their owners and extract methods (step 1)

Reviewer Instruction Pack & Campaign Communications

What reviewers are sent and told (steps 6 to 8)

Access Review Campaign Workbook

Lists, decisions and status (steps 5 to 11)

Access Review Findings & Revocation Tracker

Removals, findings and weaknesses to closure (steps 14, 15, 17)

Access Review Evidence & Audit File Checklist

The evidence file (step 18)

Access Review Outcome Report Template

The campaign report (step 20)

Segregation of Duties Conflict Matrix; Security Exception & Waiver Standard

Conflicts checked at step 11, and the exception route (Security Exception, Waiver & Segregation of Duties pack)

Adapting this template

Guidance — delete before approval

Small organisation: one campaign a quarter covering whatever is due is enough, run from a spreadsheet and a shared mailbox. Keep the dated extract, the four decisions, the fresh-extract confirmation and the sign-off: they are what an auditor tests. The day 20 close can shrink for a handful of systems; the removal windows cannot.

Regulated entity (DORA, PCI DSS): a DORA financial entity reviews access to systems supporting critical or important functions at least every six months and others at least yearly, with clear roles for granting, reviewing and revoking access (Delegated Regulation (EU) 2024/1774 Article 21(e)); limits access to what approved functions need (Regulation (EU) 2022/2554 Article 9(4)(c)). A PCI DSS entity reviews user accounts, including third-party accounts, at least every six months (7.2.4). Schedule campaigns so no system passes its frequency, and keep the evidence file per system.

IT run by a service provider: the provider takes extracts (step 3) and makes removals (step 13), but the campaign coordinator, the reviewers and the decisions stay with you. Put the extract date, format and the removal times (1 working day privileged, 5 standard) into the contract, and confirm every removal against your own fresh extract, not the provider's ticket.

Delete this section before approval.

Framework references

These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; PCI DSS v4.0.1.

Framework

Reference

Supported by

ISO/IEC 27001:2022

Annex A 5.18 — Access rights

Whole procedure: access rights reviewed, and changes made and confirmed

ISO/IEC 27001:2022

Annex A 8.2 — Privileged access rights

Privileged accounts reviewed by the system owner and a second time by information security (steps 5, 11); 1-working-day removal

ISO/IEC 27001:2022

Clause 7.5 — Documented information

Evidence file and records (steps 18, 19; Evidence retained)

NIST CSF 2.0

PR.AA-05 — “Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties”

Stages 4 to 6: permissions reviewed, and removed where not needed

DORA — Delegated Regulation (EU) 2024/1774

Article 21(e) — account management: roles for granting, reviewing and revoking access; privileged access on a need-to-use basis; removal without undue delay; review at least every six months for systems supporting critical or important functions and at least yearly for others

Roles for reviewing and revoking; timetable; regulated-entity tailoring

PCI DSS v4.0.1

Requirement 7.2.4 — user accounts and their access privileges, including third-party accounts, reviewed at least every six months

Campaign covering user and third-party accounts; regulated-entity tailoring

DORA — Regulation (EU) 2022/2554

Article 9(4)(c) — policies that limit access to information and ICT assets to what is required for legitimate and approved functions, with controls that ensure sound administration of access rights

Decisions limit access to what the job needs

Definitions

Term

Meaning in this procedure

Campaign

One round of review across the systems due, with one extract date (day 0), one decision date and one close date.

Cannot decide

The decision for an entry the reviewer cannot judge; it goes to the system owner.

Day n

The nth working day after the extract date; the extract date is day 0.

Extract

The list of every account on a system, with names, roles, permissions and last sign-in, taken on a stated date.

Fresh extract

A new extract taken after the removal windows, to confirm removals (AR-07).

Finding

Access that should not have existed, or a conflict, recorded with its cause (AR-08).

Late removal

A Revoke or Modify whose access was removed after its removal window. Every removal is then confirmed against a fresh extract.

Process weakness

A cause behind several findings, sent to the owner of the process (AR-11).

Removal window

1 working day for privileged access, 5 working days for other access, from the decision date.

Working day

Monday to Friday, excluding [[public holidays where you are]].