Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.5.18 Access Rights

1. Provisioning and Alignment Principles

anDREa manages, provisions, reviews, modifies, and removes access rights to information assets and technical environments in strict alignment with our core access control policies (Annex A.5.15). This systematic management framework satisfies ISO/IEC 27001 Annex A.5.18 and guarantees that system permissions always reflect active business needs.

The lifecycle of access rights is governed by two baseline enforcement rules:

  • The Principle of Least Privilege (PoLP): Rights are granted only if an individual explicitly requires them to execute their specific job function. Access is limited to the narrowest possible scope and provisioned for the shortest duration necessary.
  • Role-Based Access Control (RBAC): To eliminate ad-hoc permission vulnerabilities, access rights are bundled into standardized, role-specific profiles mapped directly to corporate functions within our directories.

2. Mandatory Access Review and Modification Cadence

Access permissions are subject to rigorous review to prevent permission bloat, role creep, or unauthorized residual access.

2.1 Scheduled Bi-Annual Evaluations

The designated Asset Overview conduct a formal, comprehensive review of all assigned user access permissions at least bi-annually (every six months). This check requires cross-referencing live user access profiles in our cloud environments (Microsoft Azure, Google Workspace, Zoho, GitHub) against the master personnel allocations recorded inside the anDREa People HR*.

2.2 Event-Driven Triggered Reviews

Beyond the regular calendar schedule, an immediate, ad-hoc access review loop is automatically triggered by major organizational milestones, including:

  • Changes in an employee's role, team allocation, or operational scope.
  • The modification, expiration, or formal termination of an employment contract, independent contractor agreement, or third-party vendor partnership.

2.3 Documentation and Audit Trail

Every access review cycle must be fully documented. The Asset Responsible must log the completion, findings, and any necessary corrective modifications (e.g., revoking excessive privileges) within our internal tracking system to maintain an auditable compliance trail.


3. Access Rights Removal and Offboarding

When a contract is terminated, an enterprise agreement expires, or personnel leave the company, anDREa triggers an automated Offboarding and Exit Strategy.

This workflow coordinates across our identity providers (Microsoft Entra ID and Google Workspace) to immediately suspend accounts, deactivate security tokens, and completely revoke all logical and physical access permissions simultaneously, as detailed in A.05.11 - Return of assets and A.05.16 - Identity management.