ISO 27001 Annex : A.9.2.5 Review of User Access Rights & A.9.2.6 Removal or Adjustment of Access Rights
In this article ISO 27001 Annex : A.9.2.5 Review of User Access Rights & A.9.2.6 Removal or Adjustment of Access Rights these two topic has been explained. A.9.2.5 Review of User Access Rights Control- Access rights of users should be reviewed regularly by asset owners. Implementation Guidance- The following should be considered while reviewing the access rights:- Access rights of users should be reviewed at regular intervals and after any changes, such as promotion, demotion or job termination; User access rights for moving from one role to another within the same organization should be reviewed and re-allocated; The privileged access rights authorizations should be reviewed frequently The allocation of access rights should be regularly reviewed to ensure that unauthorized privileges are not obtained; Regular reviews should be registered for changes to privileged accounts. Other Information- This control probably accounts for...