Sekit CSF · Family
Identity & Access Management
30 controls in 10 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0085Access reviews (recertification)6 mappingsAccess rights are formally reviewed periodically to confirm they remain appropriateRCF-0061Identity lifecycle6 mappingsUser accounts are formally managed from creation to deletion across all systemsRCF-0088JML (joiner-mover-leaver)7 mappingsA formal process covers access management for joiners, movers and leaversRCF-0067Least privilege / RBAC6 mappingsUsers only have access to what their role requiresRCF-0076Password policy6 mappingsStrong password requirements are formally defined and communicatedRCF-0070Privileged access management5 mappingsAdministrator accounts are strictly controlled and separated from regular accountsRCF-0082Remote access6 mappingsClear rules govern how employees access company systems remotelyRCF-0079Session management6 mappingsInactive sessions are formally required to terminate after a defined periodRCF-0073SSO & federation5 mappingsA centralised identity system allows secure access to all applications with one loginRCF-0064Strong authentication (MFA)7 mappingsA second verification step beyond password is required to access critical systems
Process
RCF-0086Access reviews (recertification)5 mappingsManagers regularly confirm their team has the correct level of accessRCF-0062Identity lifecycle6 mappingsThere is a consistent process for onboarding and offboarding user accessRCF-0089JML (joiner-mover-leaver)6 mappingsHR and IT coordinate promptly when employment status changesRCF-0068Least privilege / RBAC5 mappingsAccess rights are adjusted when roles change and removed when no longer neededRCF-0077Password policy5 mappingsEmployees consistently use a password manager and follow password hygieneRCF-0071Privileged access management6 mappingsPrivileged access is logged, time-limited and formally approvedRCF-0083Remote access5 mappingsRemote access is consistently configured securely and employees are trainedRCF-0080Session management6 mappingsUsers consistently lock screens and log out when leaving their workstationRCF-0074SSO & federation5 mappingsNew applications are integrated with the central identity system before deploymentRCF-0065Strong authentication (MFA)5 mappingsMFA is consistently applied with no informal exceptions
Technical
RCF-0087Access reviews (recertification)5 mappingsSystems automatically generate access reports to support periodic reviewsRCF-0063Identity lifecycle6 mappingsAccount lifecycle is technically enforced — access is removed automatically when someone leavesRCF-0090JML (joiner-mover-leaver)6 mappingsAccess provisioning and deprovisioning is automated through HR system integrationRCF-0069Least privilege / RBAC5 mappingsPermissions are enforced at the system level not based on user behaviourRCF-0078Password policy6 mappingsStrong password requirements are technically enforced at the system levelRCF-0072Privileged access management8 mappingsTechnical tools control and monitor all use of privileged accountsRCF-0084Remote access8 mappingsRemote connections are encrypted and restricted to approved devices onlyRCF-0081Session management6 mappingsScreen locks and session timeouts are technically enforced on all devicesRCF-0075SSO & federation6 mappingsAll critical applications authenticate through a central identity providerRCF-0066Strong authentication (MFA)5 mappingsMFA is technically enforced and cannot be bypassed
This family in ISO/IEC 27001:2022
Every framework item the family's controls map to, most-connected first — grouped by Sekit CSF family, never by the framework's own index.
This family in NIST CSF 2.0
This family in Cyber Essentials
Ask Sekura: “What evidence proves Identity & Access Management?”
Also via MCP, free with account