Provision, review and revoke access rights in line with your access policy, especially when people change roles or leave. Regular reviews catch access that should have been removed.
What an auditor, or Sekit's evidence engine, asks for.
Joiner-mover-leaver procedure
The process the company follows when someone joins, changes role, or leaves: how access and devices are granted and removed.
From the Sekit evidence catalog
In practice
This control is where access control theory meets the calendar: a periodic access review, usually quarterly, where managers confirm each team member's access still matches their current job. Auditors ask for the last completed review cycle and check whether flagged access was removed within the stated deadline, not only flagged and left open. The most common gap traces back to the joiner-mover-leaver procedure: a mover event, someone changing teams internally, that only strips old access when the review catches it months later, rather than at the moment the role changed.
Common gaps
The last completed access review flagged several accounts for removal, but the deadline passed and the access is still active with no record of why.
Internal role changes, movers rather than leavers, are not treated as a trigger for an access review, so old permissions accumulate quietly over a person's tenure.
The access review relies on managers recalling each team member's permissions from memory rather than a pulled listing from the identity provider.
Questions your auditor will ask
How often is access reviewed, and who is responsible for it?
Reference the periodic access review commitment, naming the reviewing managers, the review cadence and the removal deadline for flagged access.
What happens when the review flags access that should be removed?
Show the last completed review's flagged items alongside evidence, such as removal tickets or identity provider logs, that the access was revoked within the deadline.
How is access listed for review generated, from memory or from the system?
Point to the identity provider exports and per-application permission reports pulled directly from the systems rather than reconstructed by a manager's recollection.
Where regulation demands it
NIS2 art. 11.2 (Management of access rights) requires the same provisioning-review-revoke cycle A.5.18 describes.
ENS op.acc.4 (Proceso de gestión de derechos de acceso) is Spain's equivalent for the access rights management process.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.