Policy Register

Access review procedure

How and how often access rights are checked against need, who signs, and what happens to what is found.

How the register reads it

Also calledaccess recertification, UAR
FamilyAccess and identity
Document typeProcedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the access control policy; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe head of IT operations.
Review cadenceEvery six months for privileged access and annually for the rest is the register's default; the clause says at regular intervals and on change of role.
On the gap list whennever on its own: the register recognises it and names the clauses, but no ticked regime lists it as a separate document (its parent, access control policy, is).
TemplateNo template yet. The clauses below say what the document is expected to contain.

Which standards require it, and what each expects it to contain

1 requiring clauses, 1 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 5.18 Access rights

Provision, review, modify and remove access rights in line with the access control policy.

What the ISO 27002 guidance expects the document to say: Requires access rights to information and other associated assets to be provisioned, reviewed, modified and removed in accordance with the organisation's topic specific policy and rules on access control.

Evidence an auditor accepts: Provisioning records showing the authorisation behind each access grant, tied to the access control rules; modification records where access changed after a role change, showing removal of the previous entitlements; removal records on termination, with the date of removal against the date of departure
Common gap: Reviews lack documented corrective actions
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Access control policy · Identity and access management standard