10. Not reviewed within the interval
Access that nobody has looked at within the interval is access nobody has confirmed. The interval is the one you set; with PCI DSS ticked, user accounts read against the six months of 7.2.4, and with CIS ticked, every account against the year of 6.8.
The rule it applies
The list has a last reviewed column, and this account's cell is blank or older than the interval you set (default 12 months) before the as-at date. With PCI DSS ticked, user accounts also fire at more than 6 months (7.2.4); with CIS Controls ticked, every account at more than 12 months (6.8). Exactly the interval never fires. Without the column, the finding does not fire and every line says the column is missing.
A question for the reviewer
Who reviews this account, and when is the next review due?
Clauses
8 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| ISO/IEC 27001 | ISO/IEC 27001 A.5.18 Access rights | every account type |
| SOC 2 | SOC 2 CC6.2 Registering and authorising users before issuing credentials | every account type |
| SOC 2 | SOC 2 CC6.3 Role-based access, least privilege and segregation of duties | every account type |
| CIS Controls | CIS Controls 6.8 Define and Maintain Role-Based Access Control | every account type |
| NIST SP 800-53 | NIST SP 800-53 AC-6(7) Least privilege: Review of User Privileges | every account type |
| NIS2 | NIS2 Art. 21(2)(i) Human resources security, access control policies and asset management | every account type |
| PCI DSS | PCI DSS 7.2.4 User accounts and privileges reviewed every six months | user accounts only |
| PCI DSS | PCI DSS 7.2.5.1 Application and system account access reviewed periodically | application and system accounts only |
The first clause, set out
ISO/IEC 27001 A.5.18Access rightsAccess rights to information and associated assets are to be granted, reviewed, changed and withdrawn in line with the access control rules and policy the organization has set. Purpose (stated in ISO/IEC 27002:2022): keeps access to information and assets defined and approved against what the business needs. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.18.