Sekit CSF · Familia
Identity & Access Management
30 controles en 10 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0085Access reviews (recertification)6 mapeosAccess rights are formally reviewed periodically to confirm they remain appropriateRCF-0061Identity lifecycle6 mapeosUser accounts are formally managed from creation to deletion across all systemsRCF-0088JML (joiner-mover-leaver)7 mapeosA formal process covers access management for joiners, movers and leaversRCF-0067Least privilege / RBAC6 mapeosUsers only have access to what their role requiresRCF-0076Password policy6 mapeosStrong password requirements are formally defined and communicatedRCF-0070Privileged access management5 mapeosAdministrator accounts are strictly controlled and separated from regular accountsRCF-0082Remote access6 mapeosClear rules govern how employees access company systems remotelyRCF-0079Session management6 mapeosInactive sessions are formally required to terminate after a defined periodRCF-0073SSO & federation5 mapeosA centralised identity system allows secure access to all applications with one loginRCF-0064Strong authentication (MFA)7 mapeosA second verification step beyond password is required to access critical systems
Proceso
RCF-0086Access reviews (recertification)5 mapeosManagers regularly confirm their team has the correct level of accessRCF-0062Identity lifecycle6 mapeosThere is a consistent process for onboarding and offboarding user accessRCF-0089JML (joiner-mover-leaver)6 mapeosHR and IT coordinate promptly when employment status changesRCF-0068Least privilege / RBAC5 mapeosAccess rights are adjusted when roles change and removed when no longer neededRCF-0077Password policy5 mapeosEmployees consistently use a password manager and follow password hygieneRCF-0071Privileged access management6 mapeosPrivileged access is logged, time-limited and formally approvedRCF-0083Remote access5 mapeosRemote access is consistently configured securely and employees are trainedRCF-0080Session management6 mapeosUsers consistently lock screens and log out when leaving their workstationRCF-0074SSO & federation5 mapeosNew applications are integrated with the central identity system before deploymentRCF-0065Strong authentication (MFA)5 mapeosMFA is consistently applied with no informal exceptions
Técnica
RCF-0087Access reviews (recertification)5 mapeosSystems automatically generate access reports to support periodic reviewsRCF-0063Identity lifecycle6 mapeosAccount lifecycle is technically enforced — access is removed automatically when someone leavesRCF-0090JML (joiner-mover-leaver)6 mapeosAccess provisioning and deprovisioning is automated through HR system integrationRCF-0069Least privilege / RBAC5 mapeosPermissions are enforced at the system level not based on user behaviourRCF-0078Password policy6 mapeosStrong password requirements are technically enforced at the system levelRCF-0072Privileged access management8 mapeosTechnical tools control and monitor all use of privileged accountsRCF-0084Remote access8 mapeosRemote connections are encrypted and restricted to approved devices onlyRCF-0081Session management6 mapeosScreen locks and session timeouts are technically enforced on all devicesRCF-0075SSO & federation6 mapeosAll critical applications authenticate through a central identity providerRCF-0066Strong authentication (MFA)5 mapeosMFA is technically enforced and cannot be bypassed
Esta familia en ISO/IEC 27001:2022
Cada elemento de marco al que mapean los controles de la familia, primero los más conectados; agrupado por familia del Sekit CSF, nunca por el índice del propio marco.
Esta familia en NIST CSF 2.0
Esta familia en Cyber Essentials
Pregúntale a Sekura: «¿Qué evidencia demuestra Identity & Access Management?»
También vía MCP, gratis con cuenta