N.1.14 Access Rights Management
Control Overview
This control mandates that the organization establishes and maintains an explicit procedure to govern the full lifecycle of both logical and physical access rights. To prevent security incidents arising from excessive permissions, unauthorized access, or outdated roles, access must be systematically granted, modified, and revoked. Crucially, the organization must maintain a verifiable, chronological record (audit trail) demonstrating exactly who holds access permissions, what level of access they possess, and the precise dates on which privileges were modified or withdrawn.
Applicability Note: This control is fully applicable to the anDREa platform and directly dictates how administrative, developer, and infrastructure permissions are regulated.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement embeds authorization management deep within our ISO/IEC 27001-based ISMS, enforcing a strict policy of zero-trust and absolute accountability.
Access rights at anDREa are strictly driven by the principles of least privilege and Role-Based Access Control (RBAC). All systems, corporate environments, and platform databases are mapped back to defined organizational roles. The provision, modification, and revocation of access are executed via tracked IT workflows, creating the required historical ledger of access adjustments. To prevent permission creep, we conduct mandatory, comprehensive Access Review Policy at least biannually and immediately upon any critical employee lifecycle transition (such as role changes or offboarding).
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.05.15 - Access control | Establishes the core architecture and rules for restricting logical access to information, systems, and networks. |
| ISO/IEC 27001 | A.05.18 - Access rights | Mandates that access rights are provisioned, reviewed, modified, and removed in accordance with the access control policy. |
| Central Identity Registry | anDREa People - Asset Overview | The definitive operational matrix where corporate assets, user roles, and designated "Asset Responsibles" are logged and maintained. |
| Review Framework | Access Review Policy | Codifies the mandatory biannual cadence, methodology, and verification requirements for reviewing user access rights. |
| Audit Trails | Onboarding & Offboarding Process | Chronological system logs and ticket receipts proving the precise execution dates for granting or withdrawing platform access. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. The authorization matrices, RBAC configurations, and lifecycle revocation workflows are fully active and ledgered. Continuous Improvement: To ensure seamless third-party audits, the organization must maintain a central compliance folder where direct evidence of historical Access Reviews (such as signed review logs, screenshots, and closed tickets) is compiled and easily retrievable.