Removing what accumulated.
WHY IT IS NECESSARY
Access accumulates, and nothing removes it automatically.
WHAT TO REVIEW
Every account, against current role Privileged access External access Access to sensitive data Accounts not used recently
WHY UNUSED ACCOUNTS
They are the least noticed and the most exploitable.
WHAT TO DO ABOUT THEM
Establish whether they are needed, and disable them if not.
HOW OFTEN TO REVIEW
Proportionate to sensitivity: frequently for privileged and external access, periodically for the rest.
WHO SHOULD REVIEW
The person who understands what the role requires.
WHY NOT THE ACCOUNT HOLDER
People confirm their own access is necessary.
WHY NOT ONLY THE TECHNICAL TEAM
They know what access exists, not what the role requires.
WHAT TO ASK THE REVIEWER
Whether this person still needs each item.
WHAT TO AVOID
Reviews where everything is approved without examination.
WHY IT HAPPENS
Long lists presented without context are approved wholesale.
WHAT TO PROVIDE
Manageable lists with enough information to decide.
WHAT TO ACT ON
Removals identified, promptly.
WHY
Reviews that identify unnecessary access and change nothing are worse than none, because they document the problem.
WHAT TO TRACK
Access removed as a result.
WHY
It measures whether the review is doing anything.
WHAT TO ESTABLISH
That reviews are recorded.
WHY
They are evidence for auditors and requirements.
WHAT TO EXAMINE
Why access accumulated.
WHAT THAT USUALLY REVEALS
Role changes not triggering removal.