IAM-08: Are reviews and revalidation of user access for least privilege and separation
of duties completed with a frequency commensurate with organizational risk tolerance?
The principle of separation of duties should also be considered when conducting user access reviews.
Access should be reviewed when users resign, are terminated, change roles, and/or no longer need the authorization to carry out duties for any other reason.
Control implemented
Control ownership
Description
Review and revalidate user access for least privilege and separation
of duties with a frequency that is commensurate with organizational risk tolerance.