unified

UC-ACCESS-02 — Review user access rights periodically

All user and privileged access rights are reviewed at least annually, and more frequently for high-risk systems, by system or data owners who confirm each entitlement remains limited to business need. Unnecessary accounts and excess privileges identified in reviews are disabled or removed within a defined SLA. Completed reviews and remediation evidence are retained.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Access Control & Identity Management
type
detective
category
administrative

Details

unified_id
UC-ACCESS-02
title
Review user access rights periodically
statement
All user and privileged access rights are reviewed at least annually, and more frequently for high-risk systems, by system or data owners who confirm each entitlement remains limited to business need. Unnecessary accounts and excess privileges identified in reviews are disabled or removed within a defined SLA. Completed reviews and remediation evidence are retained.
domain
Access Control & Identity Management
control_type
detective
control_category
administrative
members
  • framework
    iso-27001
    control_id
    A.5.18
    coverage
    partial
    delta
    provisioning, adjustment, and revocation satisfied by the account lifecycle control
    relationship
    intersects_with
  • framework
    nydfs-500
    control_id
    500.7
    coverage
    partial
    delta
    least-privilege limits and termination revocation satisfied by companion access controls
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections