Identity & Access · IA-Q05

Question

Are access rights periodically reviewed and right-sized, including after job changes?

Why This Matters

Access drifts. Certifications restore least privilege and meet audit expectations.

Maturity

How to Level Up

| From → To | Actions | |—|—| |0 → 2| Schedule quarterly certifications for crown jewels; name owners.| |2 → 3| Automate attestations and revokes; evidence retention.| |3 → 4| Add usage-based outlier detection; track SLA on removals.| |4 → 5| Continuous analytics-driven right-sizing.|

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

Common Pitfalls

Compliance Mapping