NIST CSF 2.0 · derived mapping target
PR.AA-05Access permissions managed
Define access permissions in policy and enforce least privilege and separation of duties, reviewing them regularly. People should have only the access their job requires.
Mapping at a glance
PR.AA-05Access permissions managedNIST CSF 2.0
RCF-0061Identity lifecycleIdentity & Access Management · PolicyRCF-0062Identity lifecycleIdentity & Access Management · ProcessRCF-0063Identity lifecycleIdentity & Access Management · TechnicalRCF-0067Least privilege / RBACIdentity & Access Management · PolicyRCF-0068Least privilege / RBACIdentity & Access Management · Process
PR.AA-05 is covered by 60 Sekit CSF controls. +55 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0061Identity lifecycle · PolicyRCF-0062Identity lifecycle · ProcessRCF-0063Identity lifecycle · TechnicalRCF-0067Least privilege / RBAC · PolicyRCF-0068Least privilege / RBAC · ProcessRCF-0069Least privilege / RBAC · TechnicalRCF-0070Privileged access management · PolicyRCF-0071Privileged access management · ProcessRCF-0072Privileged access management · TechnicalRCF-0079Session management · PolicyRCF-0080Session management · ProcessRCF-0081Session management · TechnicalRCF-0082Remote access · PolicyRCF-0083Remote access · ProcessRCF-0084Remote access · TechnicalRCF-0085Access reviews (recertification) · PolicyRCF-0086Access reviews (recertification) · ProcessRCF-0087Access reviews (recertification) · TechnicalRCF-0088JML (joiner-mover-leaver) · PolicyRCF-0089JML (joiner-mover-leaver) · ProcessRCF-0090JML (joiner-mover-leaver) · TechnicalRCF-0136API security · PolicyRCF-0137API security · ProcessRCF-0138API security · TechnicalRCF-0166Local admin control · PolicyRCF-0167Local admin control · ProcessRCF-0168Local admin control · TechnicalRCF-0169Network segmentation · PolicyRCF-0170Network segmentation · ProcessRCF-0171Network segmentation · TechnicalRCF-0172Firewall management · PolicyRCF-0173Firewall management · ProcessRCF-0174Firewall management · TechnicalRCF-0184Zero Trust network access · PolicyRCF-0185Zero Trust network access · ProcessRCF-0186Zero Trust network access · TechnicalRCF-0187VPN management · PolicyRCF-0188VPN management · ProcessRCF-0189VPN management · TechnicalRCF-0190Wireless security · PolicyRCF-0191Wireless security · ProcessRCF-0192Wireless security · TechnicalRCF-0298Facility access control · PolicyRCF-0299Facility access control · ProcessRCF-0300Facility access control · TechnicalRCF-0301Visitor management · PolicyRCF-0302Visitor management · ProcessRCF-0303Visitor management · TechnicalRCF-0304CCTV monitoring · PolicyRCF-0305CCTV monitoring · ProcessRCF-0306CCTV monitoring · TechnicalRCF-0334Cloud IAM · PolicyRCF-0335Cloud IAM · ProcessRCF-0336Cloud IAM · TechnicalRCF-0349Multi-tenancy controls · PolicyRCF-0350Multi-tenancy controls · ProcessRCF-0351Multi-tenancy controls · TechnicalRCF-0421Network segmentation (ICS) · PolicyRCF-0422Network segmentation (ICS) · ProcessRCF-0423Network segmentation (ICS) · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Joiner-mover-leaver procedure
The process the company follows when someone joins, changes role, or leaves: how access and devices are granted and removed.
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves PR.AA-05?”
Also via MCP, free with account