@@ -0,0 +1,31 @@
|
||||
---
|
||||
id: "PER.ACC.006"
|
||||
category: "personnel/access"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-14"
|
||||
estimate-time: "30m"
|
||||
necessity: "mandatory"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC3.3", "CC6.1", "CC6.2", "CC6.3", "CC6.5"]
|
||||
---
|
||||
|
||||
# Conduct an access reviews
|
||||
|
||||
## Purpose
|
||||
|
||||
A formal/explicit process to review employee access on a quarterly/yearly basis
|
||||
is a must have in terms of security hygiene.
|
||||
|
||||
## Implementation
|
||||
|
||||
Every 3 or 6 months, plan an “Access review session” with the relevant people to
|
||||
audit accesses on all systems (that is another good reason to enable SSO). You
|
||||
need to ensure everyone has the proper access for his/her job - an account
|
||||
inactive for the last 90 days can probably be disable. If you proceed to any
|
||||
change, document it in the minutes of the meeting - those minutes will be asked
|
||||
for subsequent SOC 2 audits.
|
||||
|
||||
## Evidence
|
||||
|
||||
- Screenshot the recurring meeting invite OR the notes from the previous reviews
|
||||
Reference in New Issue
Block a user