unified
UC-ACCESS-02 — Review user access rights periodically
All user and privileged access rights are reviewed at least annually, and more frequently for high-risk systems, by system or data owners who confirm each entitlement remains limited to business need. Unnecessary accounts and excess privileges identified in reviews are disabled or removed within a defined SLA. Completed reviews and remediation evidence are retained.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Access Control & Identity Management
- type
- detective
- category
- administrative
Details
- unified_id
- UC-ACCESS-02
- title
- Review user access rights periodically
- statement
- All user and privileged access rights are reviewed at least annually, and more frequently for high-risk systems, by system or data owners who confirm each entitlement remains limited to business need. Unnecessary accounts and excess privileges identified in reviews are disabled or removed within a defined SLA. Completed reviews and remediation evidence are retained.
- domain
- Access Control & Identity Management
- control_type
- detective
- control_category
- administrative
- members
- framework
- iso-27001
- control_id
- A.5.18
- coverage
- partial
- delta
- provisioning, adjustment, and revocation satisfied by the account lifecycle control
- relationship
- intersects_with
- framework
- nydfs-500
- control_id
- 500.7
- coverage
- partial
- delta
- least-privilege limits and termination revocation satisfied by companion access controls
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-02 — Review user access rights periodically mitigates Excessive privilege and wrong assignment of access rights
- strength
- primary
- rationale
- Reviews confirm each entitlement stays business-limited and remove excess privilege, directly catching privilege creep and wrong assignment.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-02 — Review user access rights periodically
- User Access Review & Recertification operates UC-ACCESS-02 — Review user access rights periodically
- System ITGC Operation operates UC-ACCESS-02 — Review user access rights periodically
- Periodic User Access Review operates UC-ACCESS-02 — Review user access rights periodically
- UC-ACCESS-02 — Review user access rights periodically mitigates Weak account provisioning/de-registration and access review
- strength
- primary
- rationale
- Periodic owner recertification of user and privileged access is the direct detective control for the missing access-review element of this risk.
- UC-ACCESS-02 — Review user access rights periodically maps_to 500.7 — Access privileges and management
- framework
- nydfs-500
- control_id
- 500.7
- coverage
- partial
- delta
- least-privilege limits and termination revocation satisfied by companion access controls
- relationship
- intersects_with
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-02 — Review user access rights periodically maps_to A.5.18 — Access rights
- framework
- iso-27001
- control_id
- A.5.18
- coverage
- partial
- delta
- provisioning, adjustment, and revocation satisfied by the account lifecycle control
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-02 — Review user access rights periodically mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- related
- rationale
- Removing standing/excess privilege found in reviews shrinks the rights available to be abused.
- SOX ITGC Testing tests UC-ACCESS-02 — Review user access rights periodically
- SOC 2 Type II Interim Testing tests UC-ACCESS-02 — Review user access rights periodically
- UC-ACCESS-02 — Review user access rights periodically mitigates Segregation-of-duties conflicts in financial processes
- strength
- related
- rationale
- Owner recertification of accumulated entitlements detects toxic combinations that breach segregation of duties.