Expert Advice Community

A.9.2.5 Review of user access rights

  Quote
Nika Created:   Jan 12, 2021 Last commented:   Jun 03, 2022

A.9.2.5 Review of user access rights

Hello Advisera Team, 

a question to this control: A.9.2.5 Review of user access rights.

What we need and what we have now there is that user access rights are reviewed when there is a change in employees status (e.g. department or position is changed).

Is it enough or is periodical review meint here?

Thank you!

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jan 13, 2021

Please note that control A.9.2.5 of ISO 27001 Annex A states that review shall be performed at regular intervals.

Considering that, reviewing access rights only when there is a change in employees’ statuses is not enough to be compliant with this control, and you must define a periodicity for review.

This article will provide you a further explanation about access control:

These materials will also help you regarding access control:

Quote
0 1
Guest
Nick Smith Jun 01, 2022

Please can you recommend a template to use to capture reviews (whether it be an excel sheet or something similar)

Quote
0 0
Expert
Rhand Leal Jun 03, 2022

Please note that ISO 27001 does not prescribe how to document the review, so organizations can develop the form as best fit their needs.

Considering that, to record reviewed access rights you can use the Internal Audit Report template included in your toolkit, using the field Audit Trail to record this information.

In case you need a more generic approach, you can use a word or excel file.

In both cases, it is important to cover at least this information:

  • review date
  • who performed the review
  • who approved the review
  • name of system/network / service / physical area reviewed
  • results of the review: uses reviewed and if they were compliant or not with the defined access rules
Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2021

Jun 03, 2022

Suggested Topics