Demonstrating control.
WHO ASKS
Auditors Customers and buyers Regulators, in some sectors Certification schemes Insurers
WHAT THEY TYPICALLY EXAMINE
Whether access is granted on a defined basis Whether it is removed on departure Whether privileged access is controlled Whether access is reviewed Whether actions are logged
WHAT EVIDENCE THEY REQUIRE
Records of grants and approvals Leaver records showing removal Review records Logs
WHY RECORDS RATHER THAN PRACTICE
Practice cannot be demonstrated retrospectively.
WHAT TO ESTABLISH
That the process produces evidence as it operates.
WHAT COMMONLY PRODUCES FINDINGS
Leavers with active accounts Access not matching roles Privileged access widely held No evidence of review Shared accounts Missing approvals
WHY LEAVERS DOMINATE FINDINGS
It is easily tested and it is frequently wrong.
WHAT TO TEST YOURSELF
Take a list of departures and check every system.
WHY BEFORE AN AUDIT
Discovering it yourself is better than being shown.
WHAT TO PREPARE
The inventory of systems and accounts Role definitions Records of joiners, changers and leavers Review records Evidence of multi-factor authentication
WHAT TO DO ABOUT GAPS
Address them rather than presenting them as intentional.
WHY
Auditors recognise the difference.
WHAT TO ESTABLISH
Realistic processes you actually follow.
WHY
Documented processes that are not followed are a worse finding than simpler ones that are.