A.5.18 Access Rights
1. Provisioning and Alignment Principles
anDREa manages, provisions, reviews, modifies, and removes access rights to information assets and technical environments in strict alignment with our core access control policies (Annex A.5.15). This systematic management framework satisfies ISO/IEC 27001 Annex A.5.18 and guarantees that system permissions always reflect active business needs.
The lifecycle of access rights is governed by two baseline enforcement rules:
- The Principle of Least Privilege (PoLP): Rights are granted only if an individual explicitly requires them to execute their specific job function. Access is limited to the narrowest possible scope and provisioned for the shortest duration necessary.
- Role-Based Access Control (RBAC): To eliminate ad-hoc permission vulnerabilities, access rights are bundled into standardized, role-specific profiles mapped directly to corporate functions within our directories.
2. Mandatory Access Review and Modification Cadence
Access permissions are subject to rigorous review to prevent permission bloat, role creep, or unauthorized residual access.
2.1 Scheduled Bi-Annual Evaluations
The designated Asset Overview conduct a formal, comprehensive review of all assigned user access permissions at least bi-annually (every six months). This check requires cross-referencing live user access profiles in our cloud environments (Microsoft Azure, Google Workspace, Zoho, GitHub) against the master personnel allocations recorded inside the anDREa People HR*.
2.2 Event-Driven Triggered Reviews
Beyond the regular calendar schedule, an immediate, ad-hoc access review loop is automatically triggered by major organizational milestones, including:
- Changes in an employee's role, team allocation, or operational scope.
- The modification, expiration, or formal termination of an employment contract, independent contractor agreement, or third-party vendor partnership.
2.3 Documentation and Audit Trail
Every access review cycle must be fully documented. The Asset Responsible must log the completion, findings, and any necessary corrective modifications (e.g., revoking excessive privileges) within our internal tracking system to maintain an auditable compliance trail.
3. Access Rights Removal and Offboarding
When a contract is terminated, an enterprise agreement expires, or personnel leave the company, anDREa triggers an automated Offboarding and Exit Strategy.
This workflow coordinates across our identity providers (Microsoft Entra ID and Google Workspace) to immediately suspend accounts, deactivate security tokens, and completely revoke all logical and physical access permissions simultaneously, as detailed in A.05.11 - Return of assets and A.05.16 - Identity management.