Sekit CSF · Identity & Access Management · Policy
RCF-0085Access reviews (recertification)
Access rights are formally reviewed periodically to confirm they remain appropriate
Mapping at a glance
RCF-0085Access reviews (recertification)Identity & Access Management · Policy
RCF-0085 maps to 6 controls across the published frameworks. +1 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.15Access controlsupportsCommitting to a periodic access review is how A.5.15's access-based-on-need principle stays true over time, instead of only being checked the day an account is created.A.5.18Access rightssupportsCommitting in writing to a periodic access review, naming who reviews and the removal deadline, supports A.5.18's review step, though provisioning and revocation are covered by other Sekit controls.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
This topic through the other lenses
All Identity & Access Management controls
Ask Sekura: “What evidence proves RCF-0085?”
Also via MCP, free with account