Knowledgebase

Meeting Access Requirements and Audits Print

  • 0

Demonstrating control.

WHO ASKS

Auditors Customers and buyers Regulators, in some sectors Certification schemes Insurers

WHAT THEY TYPICALLY EXAMINE

Whether access is granted on a defined basis Whether it is removed on departure Whether privileged access is controlled Whether access is reviewed Whether actions are logged

WHAT EVIDENCE THEY REQUIRE

Records of grants and approvals Leaver records showing removal Review records Logs

WHY RECORDS RATHER THAN PRACTICE

Practice cannot be demonstrated retrospectively.

WHAT TO ESTABLISH

That the process produces evidence as it operates.

WHAT COMMONLY PRODUCES FINDINGS

Leavers with active accounts Access not matching roles Privileged access widely held No evidence of review Shared accounts Missing approvals

WHY LEAVERS DOMINATE FINDINGS

It is easily tested and it is frequently wrong.

WHAT TO TEST YOURSELF

Take a list of departures and check every system.

WHY BEFORE AN AUDIT

Discovering it yourself is better than being shown.

WHAT TO PREPARE

The inventory of systems and accounts Role definitions Records of joiners, changers and leavers Review records Evidence of multi-factor authentication

WHAT TO DO ABOUT GAPS

Address them rather than presenting them as intentional.

WHY

Auditors recognise the difference.

WHAT TO ESTABLISH

Realistic processes you actually follow.

WHY

Documented processes that are not followed are a worse finding than simpler ones that are.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot