Access review
“Who had access to our systems and data, and when was that last checked?”
- Who asks, and when
- Auditors, cyber-insurance underwriters, and corporate clients running vendor or outside-counsel security reviews. It is the single most frequently asked question across all three.
- What drives it
- NIST Cybersecurity Framework — the Protect function treats identity management and access control as a core category
- NIST SP 800-171 — the Access Control and Audit and Accountability families both require access to be limited and the limitation to be verifiable
- HIPAA Security Rule — administrative safeguards require information-access management and periodic evaluation
- SOC 2 — the common criteria concerned with logical access expect access to be authorised, reviewed and removed
- PCI DSS — requirement areas covering identification, authentication and access restriction by business need-to-know
- The technical control
- Role-based access in Entra ID with group-based assignment rather than per-user grants; privileged roles held just-in-time rather than standing where licensing allows; joiner-mover-leaver process actually executed on HR events; access reviewed on a defined cadence by someone who can say yes or no.
- The evidence artifact
- A dated access review record naming what was reviewed, who reviewed it, what changed as a result, and what was accepted as-is. Plus a privileged-access inventory showing who holds administrative roles today.
- How it is validated
- A reviewer checks that the record has a date, a named approver, and a decision — not merely a list. Then they sample: pick two people who left in the period and confirm their access was removed, and when.
- Where it usually fails
- The control runs and leaves no evidence that it ran. Access genuinely is reviewed, informally, by someone who remembers doing it. From the outside that is indistinguishable from never having reviewed it at all.