Sekit CSF · Identity & Access Management · Policy
RCF-0088JML (joiner-mover-leaver)
A formal process covers access management for joiners, movers and leavers
Mapping at a glance
RCF-0088JML (joiner-mover-leaver)Identity & Access Management · Policy
A.5.16Identity managementISO/IEC 27001:2022 · Annex A controlsA.5.18Access rightsISO/IEC 27001:2022 · Annex A controlsA.6.5Responsibilities after termination or change of employmentISO/IEC 27001:2022 · Annex A controlsPR.AA-01Identities and credentials managedNIST CSF 2.0PR.AA-02Identities proofed and boundNIST CSF 2.0
RCF-0088 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
A.5.16Identity managementsupportsSekit's JML procedure names who triggers each joiner, mover and leaver event and the deadline for revoking a leaver's access, but writing the procedure down does not itself run it: the automated execution A.5.16 also needs is mapped separately as a technical control.A.5.18Access rightssupportsNaming who triggers each joiner, mover and leaver event gives A.5.18's access rights process a defined starting point instead of relying on informal notice.A.6.5Responsibilities after termination or change of employmentsupportsThis policy control documents the joiner-mover-leaver procedure, naming who triggers access changes and the deadline for revoking a leaver's access, supporting A.6.5's requirement without covering the confidentiality duties that also outlast employment.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.AA-01Identities and credentials managedPR.AA-02Identities proofed and boundPR.AA-05Access permissions managed
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Joiner-mover-leaver procedure
The process the company follows when someone joins, changes role, or leaves: how access and devices are granted and removed.
From the Sekit evidence catalog
This topic through the other lenses
All Identity & Access Management controls
Ask Sekura: “What evidence proves RCF-0088?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.