Security Questionnaire Mapper
Access and identity ยท question family

Access provisioning and review: the clause the question tests

How access is granted, reviewed on a cycle and removed when people move or leave.

How the customer usually asks it

example

"How often are user access rights reviewed, and by whom?"

Read this question

Anchor clauses

6 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20225.18 Access rights
SOC 2 (Trust Services Criteria)CC6.2 Prior to granting access, registration and authorization processes are established
SIG (Shared Assessments)domain H Access Control
NIST Cybersecurity Framework 2.0PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
NIST SP 800-53 Rev 5AC-2 Account management
PCI DSS v4.0.17.2.4 All user accounts and related access privileges, including third-party/vendor accounts, are reviewed

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The access request and approval records, the last completed access review with its sign-off, and leaver records showing when access was removed.

The clauses, with what an assessor asks for

ISO 27001 5.18 Access rights

Provision, review, modify and remove access rights in line with the access control policy.

Evidence an assessor expects: Access provision records; Access review reports; Access revocation logs; Role definition documents
Where answers usually fall short: Reviews lack documented corrective actions; Access changes not tied to approved request workflow
Source: ISO/IEC 27001:2022
SOC 2 CC6.2 Prior to granting access, registration and authorization processes are established

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The registration and authorisation procedure that must complete before credentials are issued, for internal and external users; Authorisation records for users provisioned in the period, showing the requester, the approver and the access requested; Evidence credentials were issued only after authorisation, with dates supporting the sequence; Evidence of removal of access when access is no longer authorised, with the interval between the trigger and the removal; Evidence covering users whose access is administered by the entity on behalf of a customer, where that applies
Where answers usually fall short: Access granted first and approved retrospectively, which reverses the order the criterion requires; Approval by the requester's peer or by the person implementing the change, so no independent authorisation exists
Source: SOC 2 (Trust Services Criteria)
SIG domain H Access Control

What it asks for, in one line (the standard's own text is not quoted here):

Implement formal access provisioning, periodic recertification, least privilege, separation of duties, and privileged access management across systems hosting in scope data.

Evidence an assessor expects: Access management policy; User access review reports; Privileged access management tool logs; Joiner mover leaver workflows
Where answers usually fall short: Privileged accounts shared; User reviews completed without manager attestation
Source: SIG (Shared Assessments)
NIST CSF PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Evidence an assessor expects: Access policy framework with role definitions; Privileged access management deployment evidence; Periodic access reviews with sign off; Segregation of duties matrix; Just in time access workflow records
Where answers usually fall short: Standing privileges still common; Access reviews rubber stamped
Source: NIST Cybersecurity Framework 2.0
SP 800-53 AC-2 Account management

Requires accounts to be managed across their full life cycle: permitted and prohibited account types defined, account managers assigned, membership prerequisites and approvals required, accounts created, modified, disabled and removed under documented criteria, usage monitored, and access reauthorized on a defined frequency.

Evidence an assessor expects: Account type register showing which account types are permitted and which are prohibited; Provisioning and deprovisioning tickets carrying documented approval by the responsible party; Leaver reconciliation between the human resources record and account disablement dates; Periodic account recertification results with evidence that revocations were executed; Monitoring output for atypical account usage and for dormant accounts
Where answers usually fall short: Shared and service accounts sit outside the joiner mover leaver process entirely; Recertification is signed off in bulk without any account actually being removed
Source: NIST SP 800-53 Rev 5
PCI DSS 7.2.4 All user accounts and related access privileges, including third-party/vendor accounts, are reviewed

What it asks for, in one line (the standard's own text is not quoted here):

All user accounts and related access privileges, including third-party/vendor accounts, are reviewed as follows:; At least once every six months.; To ensure user accounts and access remain appropriate based on job function.

Evidence an assessor expects: Auditable consent records with timestamp, version, and channel
Where answers usually fall short: Consent capture mechanism does not record purpose, time, and version of notice shown; Withdrawal of consent not as easy as giving consent
Source: PCI DSS v4.0.1

Other families in access and identity