Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

N.1.14 Access Rights Management

Control Overview

This control mandates that the organization establishes and maintains an explicit procedure to govern the full lifecycle of both logical and physical access rights. To prevent security incidents arising from excessive permissions, unauthorized access, or outdated roles, access must be systematically granted, modified, and revoked. Crucially, the organization must maintain a verifiable, chronological record (audit trail) demonstrating exactly who holds access permissions, what level of access they possess, and the precise dates on which privileges were modified or withdrawn.

note

Applicability Note: This control is fully applicable to the anDREa platform and directly dictates how administrative, developer, and infrastructure permissions are regulated.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement embeds authorization management deep within our ISO/IEC 27001-based ISMS, enforcing a strict policy of zero-trust and absolute accountability.

Access rights at anDREa are strictly driven by the principles of least privilege and Role-Based Access Control (RBAC). All systems, corporate environments, and platform databases are mapped back to defined organizational roles. The provision, modification, and revocation of access are executed via tracked IT workflows, creating the required historical ledger of access adjustments. To prevent permission creep, we conduct mandatory, comprehensive Access Review Policy at least biannually and immediately upon any critical employee lifecycle transition (such as role changes or offboarding).


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.15 - Access controlEstablishes the core architecture and rules for restricting logical access to information, systems, and networks.
ISO/IEC 27001A.05.18 - Access rightsMandates that access rights are provisioned, reviewed, modified, and removed in accordance with the access control policy.
Central Identity RegistryanDREa People - Asset OverviewThe definitive operational matrix where corporate assets, user roles, and designated "Asset Responsibles" are logged and maintained.
Review FrameworkAccess Review PolicyCodifies the mandatory biannual cadence, methodology, and verification requirements for reviewing user access rights.
Audit TrailsOnboarding & Offboarding ProcessChronological system logs and ticket receipts proving the precise execution dates for granting or withdrawing platform access.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. The authorization matrices, RBAC configurations, and lifecycle revocation workflows are fully active and ledgered. Continuous Improvement: To ensure seamless third-party audits, the organization must maintain a central compliance folder where direct evidence of historical Access Reviews (such as signed review logs, screenshots, and closed tickets) is compiled and easily retrievable.