N.1.13 Registration and deregistration of users
Control Overview
This control mandates the establishment and implementation of a formalized identity lifecycle management procedure. The organization must securely govern how user accounts—covering full-time employees, contractors, and external vendors—are created, modified, and deactivated. To prevent security incidents caused by unauthorized system access, orphan accounts, or "privilege creep," identity creation must require rigorous verification, role assignments must adhere to the principle of least privilege, and termination must trigger the immediate, verifiable deletion or disabling of all connected accounts.
Applicability Note: This control is fully applicable to the anDREa platform and explicitly governs access to both the corporate environments and live customer-tenant environments.
Compliance & Strategic Approach
Our approach centers identity management within our ISO/IEC 27001-based ISMS, relying on trusted central identity providers to enforce uniform access boundaries.
Rather than managing disparate, siloed user directories, anDREa centralizes identity governance through Microsoft Entra ID and Google Workspace. The entire user lifecycle is governed by structured onboarding, role-change, and offboarding workflows. Account creation is strictly dependent on positive identity verification, and access rights are automatically provisioned using a strict Role-Based Access Control (RBAC) model. To ensure long-term hygiene, we enforce a strict Access Review Policy alongside a specialized "emergency brake" procedure designed to instantly revoke access across all critical environments if a high-risk security event or sudden termination occurs.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.05.16 - Identity management | Mandates full control over the lifecycle of digital identities, ensuring rigorous registration, modification, and de-registration. |
| ISO/IEC 27001 | A.05.17 - Authentication information | Governs the secure allocation, management, and protection of user authentication details (passwords, MFA tokens). |
| Operational Governance | Access Review Policy | Defines the cadence, ownership, and technical execution criteria for auditing and pruning stale or over-privileged accounts. |
| Lifecycle Workflows | Onboarding & Offboarding Process | Step-by-step verification protocols that log identity checks, account creations, and comprehensive de-provisioning records. |
| Emergency Protocols | Emergency Breaks | Direct, documented technical operations procedures allowing administrators to execute rapid, platform-wide lockouts of an identity. |
| Automated Monitoring | Identity Check Script Metrics | Internal automated checking scripts that systematically flag unmapped, inactive, or anomalous administrative accounts. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. The core identity lifecycle from verification to revocation is fully formalized, integrated into Entra ID/Google Workspace, and monitored via automated check scripts. Continuous Improvement: Advancing toward automated, API-driven de-provisioning webhooks across all secondary third-party SaaS platforms will increase operational maturity, though it is not an audit gap.