Access Provisioning
What is Access Provisioning?
The process of granting users the appropriate access rights and permissions to systems and resources based on their role and business need.
Terms that appear alongside access provisioning
Each of these is named in at least one of the same controls as access provisioning. The number is how many controls name both.
- authorization 3 shared controls
- privileged access management 3 shared controls
- access management 3 shared controls
- authentication 3 shared controls
- multi factor authentication 2 shared controls
- identity and access management 2 shared controls
- access control 2 shared controls
- cybersecurity 2 shared controls
Frameworks that govern access provisioning
What the standards actually require on access provisioning
Requirements naming access provisioning across 6 standards, quoted from the control text.
Run an access provisioning process that authorises each grant, records it, and communicates changes to data and asset access to the affected parties.
CCM-IAM-06 · User Access Provisioning →Requirement defined in ISO 27018:2019, clause 9.2.2 (User access provisioning). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.
iso-27018-2019::9.2.2 · User access provisioning →New user access to in-scope financial systems is approved and provisioned based on documented authorization aligned with job responsibilities
CO-LogicalAccess-1 · User Access Provisioning →Access provisioning, authentication, authorization, and review controls protect system resources.
SOC3-LOGICAL-ACCESS · Logical Access →Security Dimension 1 Access Control per X.805 Clause 6.1: Access Control protects against unauthorized use of network resources. Access Control ensures that only authorized personnel or devices are allowed access to network elements + stored information + info...
X805-Dim1-Access-Control-RBAC-Authorization-Resources-Network-Elements-Services-Applications · ITU-T X.805 Security Dimension 1 - Access Control + Role-Based Access Control (RBAC) + Authorization + Resources + Network Elements + Services + Applications + Access Limitations + Authorized Personnel + Discretionary + Mandatory Access Control →Provide cybersecurity awareness training to all personnel as part of the Information Security Program with frequency commensurate with risk + role-based training for personnel with privileged access + escalated training upon material change in risk + training...
NAIC-7 · Employee Training, Awareness, and Personnel Security - Section 4(D)(7) and 4(E) →Questions people ask about access provisioning
What is Access Provisioning?
Why is Access Provisioning important for compliance?
Which compliance frameworks address Access Provisioning?
Where can I learn more about Access Provisioning?
See how Access Provisioning applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.