unified

UC-ACCESS-02 — Review user access rights periodically

All user and privileged access rights are reviewed at least annually, and more frequently for high-risk systems, by system or data owners who confirm each entitlement remains limited to business need. Unnecessary accounts and excess privileges identified in reviews are disabled or removed within a defined SLA. Completed reviews and remediation evidence are retained.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-09-17T22:28:00Z (f368a6cce277)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

domain
Access Control & Identity Management
type
detective
category
administrative

Details

unified_id
UC-ACCESS-02
title
Review user access rights periodically
statement
All user and privileged access rights are reviewed at least annually, and more frequently for high-risk systems, by system or data owners who confirm each entitlement remains limited to business need. Unnecessary accounts and excess privileges identified in reviews are disabled or removed within a defined SLA. Completed reviews and remediation evidence are retained.
domain
Access Control & Identity Management
control_type
detective
control_category
administrative
members
  • framework
    iso-27001
    control_id
    A.5.18
    coverage
    partial
    delta
    provisioning, adjustment, and revocation satisfied by the account lifecycle control
    relationship
    intersects_with
  • framework
    nydfs-500
    control_id
    500.7
    coverage
    partial
    delta
    least-privilege limits and termination revocation satisfied by companion access controls
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections