Sekit CSF · Identity & Access Management · Technical
RCF-0090JML (joiner-mover-leaver)
Access provisioning and deprovisioning is automated through HR system integration
Mapping at a glance
RCF-0090JML (joiner-mover-leaver)Identity & Access Management · Technical
RCF-0090 maps to 6 controls across the published frameworks. +1 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.16Identity managementsupportsConnecting HR or the staff directory to the identity provider so lifecycle events fire automatically closes the manual relay gap that stale or orphaned accounts, A.5.16's core risk, come from.A.5.18Access rightssupportsConnecting HR to the identity provider so leaver events disable accounts automatically removes the manual relay step where A.5.18 revocations most often slip.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.AA-01Identities and credentials managedPR.AA-02Identities proofed and boundPR.AA-05Access permissions managed
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Joiner-mover-leaver procedure
The process the company follows when someone joins, changes role, or leaves: how access and devices are granted and removed.
From the Sekit evidence catalog
This topic through the other lenses
All Identity & Access Management controls
Ask Sekura: “What evidence proves RCF-0090?”
Also via MCP, free with account