Files
probo/controls/personnel/access/PER.ACC.006_periodic_access_review.md
gearnode b67e15c631 Add keep and transparency
Signed-off-by: gearnode <bryan@frimin.fr>
2025-01-15 15:50:00 +01:00

943 B

id, category, revision-version, revision-date, estimate-time, necessity, frameworks
id category revision-version revision-date estimate-time necessity frameworks
PER.ACC.006 personnel/access 1 2024-01-14 30m mandatory
name sections
soc2
CC3.3
CC6.1
CC6.2
CC6.3
CC6.5

Conduct an access reviews

Purpose

A formal/explicit process to review employee access on a quarterly/yearly basis is a must have in terms of security hygiene.

Implementation

Every 3 or 6 months, plan an “Access review session” with the relevant people to audit accesses on all systems (that is another good reason to enable SSO). You need to ensure everyone has the proper access for his/her job - an account inactive for the last 90 days can probably be disable. If you proceed to any change, document it in the minutes of the meeting - those minutes will be asked for subsequent SOC 2 audits.

Evidence

  • Screenshot the recurring meeting invite OR the notes from the previous reviews