Identity & Access · IA-Q01

Question

Has the organization defined and implemented a single access control policy that covers employees, interns, contractors, and vendors?

Why This Matters

A unified, enforced policy prevents privilege sprawl, inconsistent exceptions, and audit surprises. It’s the baseline for least privilege, measurable oversight, and faster onboarding/offboarding.

Maturity

How to Level Up

| From → To | Actions | |—|—| |0 → 2| Draft and approve a single AC policy covering all user types; publish owners and review cadence.| |2 → 3| Map jobs → roles → entitlements; enforce via IdP/SSO and gateways; record exceptions.| |3 → 4| Extend to vendors/contractors with time-boxing; quarterly metrics; remediate aged exceptions.| |4 → 5| Automate attestations; policy-as-code; exception risk scoring and time-to-close SLAs.|

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

Common Pitfalls

Compliance Mapping