Access Review Outcome Report Template
Reports campaign results in terms of risk removed and control weaknesses found rather than percentage completed.
Available soon
- Format
- Word
- Size
- 61 KB
- Length
- 17 pages
- Version
- 1.0
- Updated
What's inside
- How to use this template
- The report
- Worked example — a completed report
- Related documents
- Adapting this template
- Framework references
- Definitions
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
How to use this template
Use this report to close every access review campaign at [[Organisation Name]]. One report covers one campaign. It says what the review removed, what should never have existed, how quickly removals were made, what the review found wrong with the processes that grant and remove access, and what management must decide. The Access Review Campaign Operating Procedure governs it; the rules (AR-nn) and measures (ARM-nn) are in the Access Review Methodology.
Guidance — delete before approval
Do not lead with "100% complete". Every entry must get a decision (AR-05), so completion says nothing about risk. Lead with what was removed and why it was there (AR-12).
Take every figure from the Access Review Campaign Workbook and the Access Review Findings & Revocation Tracker; do not retype them from memory. The totals in Part B must add up to the entries reviewed.
Part | Who completes it | When |
|---|---|---|
A — Campaign and scope | Campaign coordinator | At close |
B, C — Access removed; removals on time | Campaign coordinator | When every removal is confirmed against a fresh extract |
D, E — Conflicts; quality signals | Campaign coordinator, with head of Information Security | Before the campaign is closed (AR-09) |
F — Process weaknesses | Campaign coordinator, agreed with each process owner | Before the report is sent |
G, H — What it means; decisions | Head of Information Security | Before the report is sent |
I — Sign-off | Head of Information Security; the forum reported to | At the meeting the report goes to |
Steps
- Close the campaign in the Access Review Campaign Workbook: every entry has a decision, and every Revoke and Modify is confirmed against a fresh extract in the Access Review Findings & Revocation Tracker.
- Complete Parts A to C from those two workbooks. Name every late removal and why.
- Complete Parts D and E with information security: the conflicts found and the quality checks run.
- Agree each process weakness with its owner, and a fix date, before the report goes out (Part F).
- Write Part G in plain words. Where a finding bears on a risk in the P05 Information Security Risk Register, name the risk and say whether its rating still holds.
- List the decisions needed (Part H), sign, and file the report with the campaign's evidence (Part I).
Field guidance
Field | What a good answer looks like | Common reason a report is returned |
|---|---|---|
B Access removed | Counts per system that add up, with leavers, dormant and orphan accounts shown separately. | One total, with no system and no leavers. |
C Late removals | Every late one named, with its due date, confirmation date and cause. | "A few were late". |
E Quality signals | Each check stated, even when nothing was seen. | Blank: the reader cannot tell if the check was run. |
F Process weaknesses | The cause, its owner and a date the owner agreed. | The finding repeated, with no cause and no owner. |
G Risk view | What changed in the organisation's risk, linked to the risk register. | "The campaign went well; 100% complete". |
H Decisions | A decision someone can take, with options. | "Management to note". |
The report
Guidance — delete before approval
Replace the placeholders when you adopt the template, or leave them as prompts. Keep the measure names and targets identical to the Access Review Methodology.
Part A — Campaign and scope
Completed by the campaign coordinator from the Access Review Campaign Workbook.
A1 Campaign | |||
Campaign ID | [[UAR-YYYY-Qn]] | Report date as at | [[YYYY-MM-DD — today's date]] |
Extract date AR-03 | [[YYYY-MM-DD]] | Decision deadline removal windows start | [[YYYY-MM-DD]] |
Close date | [[YYYY-MM-DD]] | Reported to | [[e.g. Executive Committee]] |
Prepared by | [[Name, Campaign coordinator]] | ||
ARM-01 reviews on time target: all | [[n of N in-scope systems reviewed within their frequency]] | ||
Systems in this campaign, from the Access Review Scope & System Inventory.
System | Name | Owner | Reviewed every | How access was extracted |
|---|---|---|---|---|
[[SYS-nn]] | [[System]] | [[Role]] | [[3 / 6 / 12]] months | [[Export, report or supplier request]] |
[[SYS-nn]] | [[System]] | [[Role]] | [[3 / 6 / 12]] months | [[Export, report or supplier request]] |
Part B — Access removed
What the review took away. Leavers, dormant and orphan accounts are within Revoke; they are the access that should not have existed at all (ARM-03 access that should not have existed).
System | Reviewed | Keep | Modify | Revoke | Cannot decide | Removals | Leavers | Dormant | Orphan |
|---|---|---|---|---|---|---|---|---|---|
[[SYS-nn]] | [[n]] | [[n]] | [[n]] | [[n]] | [[n]] | [[Modify + Revoke]] | [[n]] | [[n]] | [[n]] |
Total |
B1 Access that should not have existed (ARM-03) | |||
Access that should not have existed leaver + dormant + orphan | [[n accounts: n leavers, n dormant, n orphan — n% of entries reviewed]] | ||
Against the last campaign target: falling campaign on campaign | [[Up / down from n last campaign, and why]] | ||
Part C — Removals confirmed on time
Every Revoke or Modify must be carried out within its removal window and confirmed against a fresh extract. Windows count in working days from the decision deadline: 1 working day for privileged access, 5 working days for all other access (ARM-02 removals confirmed on time, target ≥ [[95%]]). A removal is late when the access is removed after its window, which counts from the decision deadline (or from the quality check, for a decision the quality check changed); every removal is then confirmed against a fresh extract.
System | Removals | Confirmed on time | Late | On time |
|---|---|---|---|---|
[[SYS-nn]] | [[n]] | [[n]] | [[n]] | [[n%]] |
Total | [[n% — against the target]] |
Every late removal, named: what it was, when it was due, removed and confirmed, and why it was late. Working days late count from the end of the window to the removal.
System | Late removal | Due | Removed | Confirmed | Days late | Why |
|---|---|---|---|---|---|---|
[[SYS-nn]] | [[What was removed; privileged or standard]] | [[YYYY-MM-DD]] | [[YYYY-MM-DD]] | [[YYYY-MM-DD]] | [[n]] | [[Cause; the PW-nn it points to, if any]] |
Part D — Segregation-of-duties conflicts
Leavers, dormant accounts and segregation-of-duties conflicts found in review must be raised as findings, not just removed. Each conflict is checked against the P02 Segregation of Duties Conflict Matrix; one that cannot be separated needs a compensating control and a P02 exception.
System | Who | Duties held together | P02 conflict and rating | Action | Removed / confirmed |
|---|---|---|---|---|---|
[[SYS-nn]] | [[Role]] | [[Duty and duty]] | [[SOD-xx-nn, rating]] | [[Separated / mitigated with exception ref]] | [[YYYY-MM-DD / YYYY-MM-DD]] |
Part E — Quality signals seen
Campaign quality must be checked for rubber-stamping before the campaign is closed. The check runs on day 17 of the campaign timetable in the Access Review Campaign Operating Procedure — after the decision deadline and before close — so a list re-reviewed because of it is re-decided in that time. State each check, whether it was seen, and what was done.
Signal | Seen? | What was done |
|---|---|---|
A reviewer keeps 100% of a large list (more than [[25]] entries) in one sitting | [[No / Yes — where, how many]] | [[Sample taken, re-review, decision changed]] |
Decisions made faster than [[5]] seconds each on average | [[No / Yes — where, how many]] | [[Sample taken, re-review, decision changed]] |
Leavers or dormant accounts (no sign-in for [[90]] days) marked Keep | [[No / Yes — where, how many]] | [[Sample taken, re-review, decision changed]] |
Privileged or generic accounts marked Keep without a named owner | [[No / Yes — where, how many]] | [[Sample taken, re-review, decision changed]] |
Part F — Process weaknesses
Findings that show a process weakness (for example, leavers not removed) must go to the owner of that process with a fix and a date. A weakness is the cause behind findings, not the findings themselves (ARM-04 process weaknesses open).
ID | Weakness | Owner | Fix due | Status |
|---|---|---|---|---|
[[PW-nn]] | [[The process that failed, and the findings that show it]] | [[Process owner]] | [[YYYY-MM-DD]] | [[Open / Fixed]] |
F1 Headline measures | |||
ARM-02 removals confirmed on time target ≥ [[95%]] | [[n of N (n%) — against the target; n late]] | ||
ARM-04 process weaknesses open target: zero past their date | [[n open, n past their date]] | ||
Part G — What it means
Campaign results must be reported as risk removed and weaknesses found, not only as percentage completed. Write for a reader who will not open the workbook. Link each point to the risk it changes.
G1 Risk view (AR-12) | |||
In three sentences risk removed and weaknesses found | [[What was removed, what should never have existed, and why — not the percentage completed]] | ||
Privileged access P05 Information Security Risk Register | [[Privileged findings and late removals; the P05 risk they bear on, and whether its rating still holds]] | ||
Leavers and dormant accounts | [[Where they were, and the process weakness behind them]] | ||
Supplier-run systems P06 Supplier Security Risk Register | [[Any supplier that could not meet the removal windows, and the effect]] | ||
Segregation of duties | [[Conflicts found; separated or mitigated]] | ||
Part H — Decisions needed
What the forum is asked to decide. Each decision has an owner; a decision not taken is recorded as not taken.
Ref | Decision needed | Owner | Outcome |
|---|---|---|---|
[[DN-nn]] | [[What must be decided, and the options]] | [[Role]] | [[Agreed / not agreed — minute ref]] |
Part I — Sign-off
Each campaign must keep an evidence file: scope, extracts, decisions, changes, confirmation and sign-off. This report closes the campaign's evidence file.
I1 Signatures | |||
Prepared by | [[Name, Campaign coordinator]] | Signature and date | [[Signature, date]] |
Reviewed by Head of Information Security | [[Name, role]] | Signature and date | [[Signature, date]] |
Accepted by the forum reported to | [[Forum, chair]] | Meeting and minute | [[Date, minute reference]] |
Evidence file AR-10 | [[Location / campaign ID]] | ||
Worked example — a completed report
The report on campaign UAR-2026-Q3 for a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. It uses the campaign's results exactly as in the other P07 documents; the organisation, roles and dates are fictional. The report date is fixed at 2026-09-30 so the example does not change; in your report, use today's date.
Guidance — delete before approval
How the figures are derived: removals are Modify plus Revoke (22 + 47 = 69); on time is removals less late (69 − 4 = 65, 94.2%); access that should not have existed is leavers plus dormant plus orphan (13 + 20 + 3 = 36). Due dates are the decision deadline, 2026-09-15, plus 1 working day (privileged, 2026-09-16) or 5 working days (all others, 2026-09-22).
Note what the report leads with: not that all 495 entries were decided, but that 36 accounts should never have existed and why. The 4 privileged ones are linked to P05 risk R-07 because they bear on the likelihood its owner assumed.
Delete this worked example from your adopted template.
Part A — Campaign and scope
Completed by the campaign coordinator from the Access Review Campaign Workbook.
A1 Campaign — EXAMPLE | |||
Campaign ID | UAR-2026-Q3 | Report date as at | 2026-09-30 (EXAMPLE — replace with today's date) |
Extract date AR-03 | 2026-09-01 | Decision deadline removal windows start | 2026-09-15 |
Close date | 2026-09-29 | Reported to | Executive Committee |
Prepared by | Information Security Manager (campaign coordinator) | ||
ARM-01 reviews on time target: all | 5 of 5 in-scope systems reviewed within their frequency (target: all) | ||
Systems in this campaign, from the Access Review Scope & System Inventory.
System | Name | Owner | Reviewed every | How access was extracted |
|---|---|---|---|---|
SYS-01 | ERP (hosted; P06 SUP-004) | Chief Financial Officer | 6 months | Supplier-run user report, requested by ticket |
SYS-02 | Warehouse management system | Head of Logistics | 6 months | Admin console export |
SYS-03 | Directory administrator groups | Head of IT | 3 months | Group membership export |
SYS-04 | Online ordering admin console | Chief Operating Officer | 3 months | Admin console export |
SYS-05 | Shared finance drive | Chief Financial Officer | 12 months | Permissions report |
Part B — Access removed
What the review took away. Leavers, dormant and orphan accounts are within Revoke; they are the access that should not have existed at all (ARM-03 access that should not have existed).
System | Reviewed | Keep | Modify | Revoke | Cannot decide | Removals | Leavers | Dormant | Orphan |
|---|---|---|---|---|---|---|---|---|---|
SYS-01 | 164 | 139 | 11 | 12 | 2 | 23 | 3 | 6 | 1 |
SYS-02 | 212 | 188 | 6 | 18 | 0 | 24 | 7 | 9 | 0 |
SYS-03 | 14 | 10 | 1 | 3 | 0 | 4 | 1 | 0 | 1 |
SYS-04 | 9 | 7 | 0 | 2 | 0 | 2 | 0 | 1 | 1 |
SYS-05 | 96 | 80 | 4 | 12 | 0 | 16 | 2 | 4 | 0 |
Total | 495 | 424 | 22 | 47 | 2 | 69 | 13 | 20 | 3 |
B1 Access that should not have existed (ARM-03) — EXAMPLE | |||
Access that should not have existed leaver + dormant + orphan | 36 accounts: 13 leavers, 20 dormant, 3 orphan — 7.3% of the 495 entries reviewed | ||
Against the last campaign target: falling campaign on campaign | First campaign reported this way: these figures are the baseline for the next | ||
Part C — Removals confirmed on time
Every Revoke or Modify must be carried out within its removal window and confirmed against a fresh extract. Windows count in working days from the decision deadline: 1 working day for privileged access, 5 working days for all other access (ARM-02 removals confirmed on time, target ≥ [[95%]]). A removal is late when the access is removed after its window, which counts from the decision deadline (or from the quality check, for a decision the quality check changed); every removal is then confirmed against a fresh extract.
System | Removals | Confirmed on time | Late | On time |
|---|---|---|---|---|
SYS-01 | 23 | 20 | 3 | 87.0% |
SYS-02 | 24 | 24 | 0 | 100.0% |
SYS-03 | 4 | 4 | 0 | 100.0% |
SYS-04 | 2 | 2 | 0 | 100.0% |
SYS-05 | 16 | 15 | 1 | 93.8% |
Total | 69 | 65 | 4 | 94.2% |
Every late removal, named: what it was, when it was due, removed and confirmed, and why it was late. Working days late count from the end of the window to the removal.
System | Late removal | Due | Removed | Confirmed | Days late | Why |
|---|---|---|---|---|---|---|
SYS-01 | Finance administrator role removed from 3 accounts (2 Modify, 1 Revoke) (privileged) | 2026-09-16 | 2026-09-22 | 2026-09-23 | 4 | The ERP provider (P06 SUP-004) acts on a removal ticket in 5 working days; privileged access must go in 1 (PW-02). |
SYS-05 | A leaver's access to the shared finance drive (Revoke) (standard) | 2026-09-22 | 2026-09-24 | 2026-09-24 | 2 | The access also came through a nested group. The fresh extract showed it still present, so it was removed a second time. A one-off: nested groups are now on the administrator's removal checklist. |
Part D — Segregation-of-duties conflicts
Leavers, dormant accounts and segregation-of-duties conflicts found in review must be raised as findings, not just removed. Each conflict is checked against the P02 Segregation of Duties Conflict Matrix; one that cannot be separated needs a compensating control and a P02 exception.
System | Who | Duties held together | P02 conflict and rating | Action | Removed / confirmed |
|---|---|---|---|---|---|
SYS-01 | Accounts payable supervisor | Create or change suppliers and their bank details; approve payments | SOD-FI-01, rated High | Separated by a Modify; no exception. Supplier-maintenance permission removed. Raised as a finding (AR-08). | 2026-09-22 / 2026-09-23 |
Part E — Quality signals seen
Campaign quality must be checked for rubber-stamping before the campaign is closed. The check runs on day 17 of the campaign timetable in the Access Review Campaign Operating Procedure — after the decision deadline and before close — so a list re-reviewed because of it is re-decided in that time. State each check, whether it was seen, and what was done.
Signal | Seen? | What was done |
|---|---|---|
A reviewer keeps 100% of a large list (more than [[25]] entries) in one sitting | Yes — one SYS-02 reviewer kept all 38 entries in one sitting | Found in the quality check on 2026-09-24, after the decision deadline. Information security sampled 10 of the 38; the reviewer re-reviewed the whole list before close. |
Decisions made faster than [[5]] seconds each on average | Yes — the same reviewer, about 3 seconds a decision | As above. |
Leavers or dormant accounts (no sign-in for [[90]] days) marked Keep | Yes — 2 dormant accounts in the same list, marked Keep | Found in the sample; corrected to Revoke in the re-review. The 2 are in SYS-02's Revoke and dormant counts. |
Privileged or generic accounts marked Keep without a named owner | No | Every privileged and generic account kept has a named owner. SYS-04's orphan privileged account (j.harper, in the Access Review Campaign Workbook) was revoked by the reviewer, not kept. |
Part F — Process weaknesses
Findings that show a process weakness (for example, leavers not removed) must go to the owner of that process with a fix and a date. A weakness is the cause behind findings, not the findings themselves (ARM-04 process weaknesses open).
ID | Weakness | Owner | Fix due | Status |
|---|---|---|---|---|
PW-01 | Warehouse leavers are not removed from the warehouse system: HR's leaver notice does not reach its owner | HR Director | 2026-11-30 | Open |
PW-02 | The ERP provider takes 5 working days to remove users; our window is 5 for standard access and 1 for privileged | Chief Financial Officer | 2026-12-15 | Open |
F1 Headline measures — EXAMPLE | |||
ARM-02 removals confirmed on time target ≥ [[95%]] | 65 of 69 (94.2%) — below the 95% target; 4 late | ||
ARM-04 process weaknesses open target: zero past their date | 2 open, 0 past their date (target: zero past their date) | ||
Part G — What it means
Campaign results must be reported as risk removed and weaknesses found, not only as percentage completed. Write for a reader who will not open the workbook. Link each point to the risk it changes.
G1 Risk view (AR-12) — EXAMPLE | |||
In three sentences risk removed and weaknesses found | The review removed or reduced 69 pieces of access (47 revoked, 22 modified) out of 495 reviewed. 36 accounts should not have existed at all, 4 of them with administrator access. The main cause is a leaver process that does not reach the warehouse system (PW-01). Removals were 94.2% on time against 95%, ; of the 4 late removals, 3 were privileged ERP access the provider cannot remove fast enough (PW-02) and 1 was a standard SYS-05 removal missed through a nested group. | ||
Privileged access P05 Information Security Risk Register | 4 privileged accounts that should not have existed on SYS-03 and SYS-04, and 3 privileged ERP removals made 4 working days after their window. P05 R-07 administrator misuses privileged access — owner Head of IT; residual impact 3 Major, likelihood 1 Unlikely, score 3 (Low). The likelihood rating assumes privileged access is kept to people who need it; this campaign shows it was not, until now (DN-02). | ||
Leavers and dormant accounts | 13 leavers still had access, 7 of them on SYS-02, the warehouse management system. Removing them fixes this quarter; PW-01 fixes the cause. | ||
Supplier-run systems P06 Supplier Security Risk Register | The ERP (SYS-01, P06 SUP-004) is run by a supplier whose removal time is longer than our window for privileged access. Until PW-02 is fixed, privileged ERP access stays for up to 4 working days longer than it should after a decision (DN-01). | ||
Segregation of duties | 1 High conflict (P02 SOD-FI-01) found and separated by a Modify, removed 2026-09-22 and confirmed on the fresh extract 2026-09-23. No compensating control or exception is needed. | ||
Part H — Decisions needed
What the forum is asked to decide. Each decision has an owner; a decision not taken is recorded as not taken.
Ref | Decision needed | Owner | Outcome |
|---|---|---|---|
DN-01 | Agree a 1-working-day removal time for privileged ERP access with the ERP provider (P06 SUP-004), or approve a P02 exception with a compensating control until the contract is changed (PW-02). | Chief Financial Officer | [[Agreed / not agreed — minute ref]] |
DN-02 | Reassess P05 risk R-07 (administrator misuses privileged access): the review found privileged accounts that should not have existed, so the control its rating relies on was weaker than assumed. | Head of IT | [[Agreed / not agreed — minute ref]] |
DN-03 | Approve the next campaign: privileged and administrator access, extract on 2026-12-01. | Head of Information Security | [[Agreed / not agreed — minute ref]] |
Part I — Sign-off
Each campaign must keep an evidence file: scope, extracts, decisions, changes, confirmation and sign-off. This report closes the campaign's evidence file.
I1 Signatures — EXAMPLE | |||
Prepared by | Information Security Manager (campaign coordinator) | Signature and date | Signed, 2026-09-30 |
Reviewed by Head of Information Security | Head of Information Security | Signature and date | Signed, 2026-09-30 |
Accepted by the forum reported to | Executive Committee, chaired by [[Chief Executive]] | Meeting and minute | [[Meeting date and minute reference]] |
Evidence file AR-10 | [[Evidence file location]] / UAR-2026-Q3 | ||
Related documents
Document | Relationship |
|---|---|
Access Review Methodology | The rules (AR-01 to AR-12) and measures (ARM-01 to ARM-04) this report applies |
Access Review Campaign Operating Procedure | The procedure that governs this report |
Access Review Scope & System Inventory | The systems in scope, their owners and frequency (Part A) |
Access Review Campaign Workbook | Decisions per system (Part B) |
Access Review Findings & Revocation Tracker | Removals, confirmation dates and findings (Parts B to D) |
Access Review Evidence & Audit File Checklist | The evidence file this report closes (Part I) |
Reviewer Instruction Pack & Campaign Communications | The closure note that tells reviewers what the campaign found |
P02 Segregation of Duties Conflict Matrix | Conflicts found in review (Part D) |
P05 Information Security Risk Register | The risks a finding bears on (Part G) |
P06 Supplier Security Risk Register | Suppliers that run in-scope systems and their removal times (Part G) |
Adapting this template
Guidance — delete before approval
Small organisation: Parts A, B, C, F and I on one or two pages are enough; keep Part C's list of late removals even if it is one line. Where the person who ran the campaign is also the one who reviews the report, have it accepted by a director who did not review access in the campaign.
Regulated entity: NIS2 Article 21(2)(i) expects access control to be applied and its effectiveness assessed; this report is that assessment for each campaign. Under DORA Article 9(4)(c) and Delegated Regulation (EU) 2024/1774 Article 21(e), show in Part A that systems supporting critical or important functions were reviewed within six months and others within a year, and in Part C that access was removed without undue delay; report generic and shared accounts found (Article 21(c)). For PCI DSS, show in Part A that user accounts in scope, including third-party accounts, were reviewed within six months (7.2.4) and application and system accounts at the frequency your targeted risk analysis sets (7.2.5.1), and in Part B that inactive accounts were removed or disabled within 90 days (8.2.6).
IT run by a service provider: the provider's extracts and removal times drive Parts A and C. Report its late removals by name, as the EXAMPLE does for the ERP provider (PW-02), and take them to the supplier review in the P06 Supplier Security Risk Register rather than absorbing them.
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; PCI DSS v4.0.1.
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Clause 9.1 — Monitoring, measurement, analysis and evaluation | Parts B, C and F1: the headline measures ARM-01 to ARM-04, measured and evaluated each campaign |
ISO/IEC 27001:2022 | Annex A 5.18 — Access rights | Parts B to D: access rights reviewed, removed and confirmed |
NIST CSF 2.0 | ID.IM-01 — “Improvements are identified from evaluations” | Parts F and H: improvements identified from the campaign, with owners and dates |
NIST CSF 2.0 | PR.AA-05 — “Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties” | Parts B and D: least privilege and separation of duties reviewed and enforced |
DORA — Delegated Regulation (EU) 2024/1774 | Article 21(e) — account management: roles for granting, reviewing and revoking access; privileged access on a need-to-use basis; removal without undue delay; review at least every six months for systems supporting critical or important functions and at least yearly for others | Parts A and C: review frequency by system, and removal without undue delay |
NIS2 — Directive (EU) 2022/2555 | Article 21(2)(i) — “human resources security, access control policies and asset management” | Part G: the effectiveness of access control assessed and reported |
Definitions
Term | Meaning in this report |
|---|---|
Access that should not have existed | Leaver, dormant and orphan accounts found in the campaign (ARM-03). |
Dormant account | An account with no sign-in for more than [[90]] calendar days, or never used. |
Late removal | A removal is late when the access is removed after its window, which counts from the decision deadline (or from the quality check, for a decision the quality check changed); every removal is then confirmed against a fresh extract. |
Leaver | Someone who has left the organisation, or whose contract has ended, but still has access. |
Orphan account | An account that matches no current person and has no named owner. |
Process weakness | The cause behind findings, such as a leaver notice that does not reach a system owner; sent to that process's owner with a fix and a date (AR-11). |
Removal window | The time allowed to carry out a Revoke or Modify, from the decision deadline: 1 working day for privileged access, 5 working days for all other access. |
Removals | Modify plus Revoke decisions. |
Segregation-of-duties conflict | One person holding two duties that should be split, so they could make and hide a wrong change or payment. |
AR-nn, ARM-nn, PW-nn | Rule and measure numbers in the Access Review Methodology; process weaknesses (PW-nn) numbered campaign by campaign in this report. |