Skip to content
BCN-T2-IAM-002Tier 2 · RegulatoryIdentity & Access Management

Missing Periodic Access Reviews

No recurring, evidenced certification that granted access remains appropriate.

Remediation SLA
30 days
Tier
2 · Regulatory
Domain
Identity
Escalation
Security manager review at 14 days

What this finding is

Access rights are granted but never systematically re-examined. There is no recurring process in which an accountable owner confirms that each identity's access remains appropriate, and no retained evidence of such a review having occurred. The finding covers both the absence of the process and a process that runs without producing auditable records.

Why it is Tier 2

Access review is explicitly required by SOC 2, ISO 27001, and PCI DSS, and is tested by sampling — an assessor selects identities and asks for the certification record. Absent records are a citable deficiency regardless of whether the underlying access is appropriate. Operationally, the absence of review is the mechanism by which privilege accumulates: without it, access granted for a temporary project persists for years and eventually becomes BCN-T1-IAM-002.

Most common misclassification

Discovering excessive privilege during a review is a separate finding — record the specific privilege under BCN-T1-IAM-002 or BCN-T3-IAM-001 and keep this finding scoped to the absence of the process.

How to detect it

  1. 1Ask for the last completed review and its evidence; inability to produce it is the finding.
  2. 2Check leaver processing by sampling recent departures and confirming access was revoked within the defined period.
  3. 3Look for orphaned accounts with no active owner, and for accounts whose last authentication predates their owner's role change.
  4. 4Confirm reviews cover third-party, contractor, and service identities, which are typically excluded from HR-triggered processes.

How to remediate it

Steps are ordered. The first step is the one that reduces exposure fastest, which is not always the one that closes the finding.

  1. 1Define the review cycle per the strictest applicable requirement — typically quarterly for privileged access, annually for standard.
  2. 2Assign accountable reviewers who understand the business context; a review performed by IT alone is evidence of process, not of appropriateness.
  3. 3Automate campaign generation and evidence capture, since manual reviews degrade after the first cycle.
  4. 4Integrate with joiner-mover-leaver so that role changes trigger review rather than relying on the periodic cycle.
  5. 5Retain completed campaigns with reviewer identity and timestamp as the audit artefact.

How to verify the fix

A completed review campaign exists for the current period covering all in-scope identities, with per-reviewer attestations retained, and sampled revocations are confirmed applied in the target system.

Mappings

Attacker techniques

Compliance mappings

  • SOC 2
    CC6.2 / CC6.3 — access is reviewed
  • PCI DSS v4.0
    7.2.4 — review user accounts every six months
  • ISO/IEC 27001:2022
    A.5.18 — access rights

Tools that surface this

Entra ID access reviewsAWS IAM Access AnalyzerSailPoint