Set and enforce rules for who can access which information and systems, based on business and security needs. Granting only the access people actually require limits the damage from any single account.
What an auditor, or Sekit's evidence engine, asks for.
MFA enrollment evidence
The proof that a second verification step (beyond the password) is required to access important systems.
From the Sekit evidence catalog
In practice
Access control in practice means role-based permissions in the identity provider, MFA required everywhere that matters, and no shared logins standing in for individual accounts. Auditors pull the MFA enrolment evidence and cross-check it against the full user list looking for gaps: contractors, service accounts, or a few long-tenured employees grandfathered out of enrolment years ago and never circled back to. The most common finding is access granted by copying an existing colleague's permissions rather than from a documented role definition, which quietly accumulates privilege nobody can explain months later.
Common gaps
A handful of long-tenured accounts were never enrolled in MFA when the requirement was rolled out and nobody has gone back to close that gap.
New hires are granted access by copying a colleague's existing permissions rather than from a documented role definition, so nobody can explain why each person has what they have.
Shared or generic logins are still used for a legacy system because migrating it to individual accounts was deprioritised.
Questions your auditor will ask
How do you decide what access a given person should have?
Point to the role definitions that state the access each role needs, granted from that definition rather than by copying an existing colleague's permissions.
Is multi-factor authentication enforced everywhere it should be?
Show the MFA enrolment evidence covering email, the identity platform, remote access and every system holding important business data, including known coverage gaps and the plan to close them.
How is administrative access handled differently from regular access?
Describe the separate, approved administrative accounts, tracked in a current register, distinct from each person's everyday login.
What stops access from accumulating as people change roles over time?
Reference the periodic access review that checks current access against current duties and removes what a role change made unnecessary.
Where regulation demands it
NIS2 art. 11.1 (Access control policy) requires the same access-by-need approach A.5.15 asks organizations to enforce.
ENS op.acc.2 (Requisitos de acceso) sets the equivalent expectation for defined access requirements tied to business need.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.