Manage digital identities across their full lifecycle, from creation to removal, so every account maps to a known person or service. Stale or shared identities are a frequent source of breaches.
What an auditor, or Sekit's evidence engine, asks for.
Joiner-mover-leaver procedure
The process the company follows when someone joins, changes role, or leaves: how access and devices are granted and removed.
From the Sekit evidence catalog
In practice
The practical version of this control is one identity per person, wired through a central identity provider, with the joiner-mover-leaver procedure as the operating document auditors ask for by name. What breaks in real companies is the manual step in the middle: HR tells a manager, the manager tells IT, and somewhere in that relay a leaver's account stays active for weeks because nobody closed the loop. Auditors test this directly by asking for a list of accounts disabled in the last quarter and comparing dates against real departure dates from HR records.
Common gaps
The joiner-mover-leaver procedure exists on paper, but leaver accounts stay active for one to three weeks past the departure date because the HR-to-IT handoff is manual.
Service accounts and shared mailboxes are not tied to any named individual, so nobody can say who is accountable if one of them is compromised.
A mover event, an internal role change, only removes old access when someone happens to notice, rather than as an automatic step of the transfer.
Questions your auditor will ask
How does an account get created, and how is it tied to a real person?
Walk through the joiner-mover-leaver procedure's onboarding step, showing the account created against a verified HR record rather than a free-text request.
What happens to an account the day someone leaves?
Point to the leaver step of the procedure and the deadline it sets for disabling access, ideally same-day, plus evidence of recent leaver dates matched against disable dates.
Are there any shared or generic accounts, and how are they controlled?
Identify any shared logins that remain, the business reason each one still exists, and the compensating control, such as logged access, applied to it.
Where regulation demands it
NIS2 art. 11.5 (Identification) requires the same mapping of every account to a known person or service.
ENS op.acc.1 (Identificación) is Spain's equivalent baseline for identity management across its lifecycle.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.