Expert Advice Community

Guest

Termination of job - activity

  Quote
Guest
Guest user Created:   Mar 27, 2018 Last commented:   Mar 27, 2018

Termination of job - activity

I have a question is ISO 27001 contains any control that mentioned the period of time an AD account should be deleted/removed after disabling he account when leaving the company .
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 27, 2018

Answer: ISO 27001 does not prescribe how to implement its requirements or controls, only what needs to be achieved.

Considering that, for the scenario you stated you can consider the control  A.9.2.6 - Removal or adjustment of access rights as basis to support your need to manage users's access rights, but for the definition of specific period of time for account deletion / removal you must consider the perceived risks (results of risk assessment) and legal requirements (e.g., laws, regulations and contracts) that must be fulfilled.

These articles will provide you further explanation about controls selection and access control:
- The basic logic of ISO 27001: How does information security work? https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/
- How to handle access control according to ISO 27001 https://advisera.com/27001academy/blog/2015/07/27/how-to-handle-access-control-according-to-iso-27001/

These materials will also help you regarding controls selection and access control:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 27, 2018

Mar 27, 2018