Missing Periodic Access Reviews
No recurring, evidenced certification that granted access remains appropriate.
- Remediation SLA
- 30 days
- Tier
- 2 · Regulatory
- Domain
- Identity
- Escalation
- Security manager review at 14 days
What this finding is
Access rights are granted but never systematically re-examined. There is no recurring process in which an accountable owner confirms that each identity's access remains appropriate, and no retained evidence of such a review having occurred. The finding covers both the absence of the process and a process that runs without producing auditable records.
Why it is Tier 2
Access review is explicitly required by SOC 2, ISO 27001, and PCI DSS, and is tested by sampling — an assessor selects identities and asks for the certification record. Absent records are a citable deficiency regardless of whether the underlying access is appropriate. Operationally, the absence of review is the mechanism by which privilege accumulates: without it, access granted for a temporary project persists for years and eventually becomes BCN-T1-IAM-002.
Most common misclassification
How to detect it
- 1Ask for the last completed review and its evidence; inability to produce it is the finding.
- 2Check leaver processing by sampling recent departures and confirming access was revoked within the defined period.
- 3Look for orphaned accounts with no active owner, and for accounts whose last authentication predates their owner's role change.
- 4Confirm reviews cover third-party, contractor, and service identities, which are typically excluded from HR-triggered processes.
How to remediate it
Steps are ordered. The first step is the one that reduces exposure fastest, which is not always the one that closes the finding.
- 1Define the review cycle per the strictest applicable requirement — typically quarterly for privileged access, annually for standard.
- 2Assign accountable reviewers who understand the business context; a review performed by IT alone is evidence of process, not of appropriateness.
- 3Automate campaign generation and evidence capture, since manual reviews degrade after the first cycle.
- 4Integrate with joiner-mover-leaver so that role changes trigger review rather than relying on the periodic cycle.
- 5Retain completed campaigns with reviewer identity and timestamp as the audit artefact.
How to verify the fix
A completed review campaign exists for the current period covering all in-scope identities, with per-reviewer attestations retained, and sampled revocations are confirmed applied in the target system.
Mappings
Attacker techniques
- T1078Valid Accounts
Compliance mappings
- SOC 2CC6.2 / CC6.3 — access is reviewed
- PCI DSS v4.07.2.4 — review user accounts every six months
- ISO/IEC 27001:2022A.5.18 — access rights