graphgrc

SCF - IAC-17 - Periodic Review of Account Privileges

Mechanisms exist to periodically-review the privileges assigned to individuals and service accounts to validate the need for such privileges and reassign or remove unnecessary privileges, as necessary.

Mapped framework controls

ISO 27002

SOC 2

Control questions

Does the organization periodically-review the privileges assigned to individuals and service accounts to validate the need for such privileges and reassign or remove unnecessary privileges, as necessary?