Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

N.1.13 Registration and deregistration of users

Control Overview

This control mandates the establishment and implementation of a formalized identity lifecycle management procedure. The organization must securely govern how user accounts—covering full-time employees, contractors, and external vendors—are created, modified, and deactivated. To prevent security incidents caused by unauthorized system access, orphan accounts, or "privilege creep," identity creation must require rigorous verification, role assignments must adhere to the principle of least privilege, and termination must trigger the immediate, verifiable deletion or disabling of all connected accounts.

note

Applicability Note: This control is fully applicable to the anDREa platform and explicitly governs access to both the corporate environments and live customer-tenant environments.

Compliance & Strategic Approach

Our approach centers identity management within our ISO/IEC 27001-based ISMS, relying on trusted central identity providers to enforce uniform access boundaries.

Rather than managing disparate, siloed user directories, anDREa centralizes identity governance through Microsoft Entra ID and Google Workspace. The entire user lifecycle is governed by structured onboarding, role-change, and offboarding workflows. Account creation is strictly dependent on positive identity verification, and access rights are automatically provisioned using a strict Role-Based Access Control (RBAC) model. To ensure long-term hygiene, we enforce a strict Access Review Policy alongside a specialized "emergency brake" procedure designed to instantly revoke access across all critical environments if a high-risk security event or sudden termination occurs.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.16 - Identity managementMandates full control over the lifecycle of digital identities, ensuring rigorous registration, modification, and de-registration.
ISO/IEC 27001A.05.17 - Authentication informationGoverns the secure allocation, management, and protection of user authentication details (passwords, MFA tokens).
Operational GovernanceAccess Review PolicyDefines the cadence, ownership, and technical execution criteria for auditing and pruning stale or over-privileged accounts.
Lifecycle WorkflowsOnboarding & Offboarding ProcessStep-by-step verification protocols that log identity checks, account creations, and comprehensive de-provisioning records.
Emergency ProtocolsEmergency BreaksDirect, documented technical operations procedures allowing administrators to execute rapid, platform-wide lockouts of an identity.
Automated MonitoringIdentity Check Script MetricsInternal automated checking scripts that systematically flag unmapped, inactive, or anomalous administrative accounts.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. The core identity lifecycle from verification to revocation is fully formalized, integrated into Entra ID/Google Workspace, and monitored via automated check scripts. Continuous Improvement: Advancing toward automated, API-driven de-provisioning webhooks across all secondary third-party SaaS platforms will increase operational maturity, though it is not an audit gap.