Skip to content

Access Review

What is Access Review?

A periodic evaluation of user access rights and permissions to verify they remain appropriate, required by most compliance frameworks.

Information Security

Each of these is named in at least one of the same controls as access review. The number is how many controls name both.

What the standards actually require on access review

Requirements naming access review across 6 standards, quoted from the control text.

Physical access rights to data centers and restricted areas are reviewed periodically by responsible owners

CO-PhysicalAccess-2 · Physical Access Review

Recertify user access against least privilege and separation of duties at a frequency set by the organisation's risk tolerance, and withdraw what is no longer justified.

CCM-IAM-08 · User Access Review

On parental request, and after reasonable verification, the operator provides the parent with a description of the types of PI collected from the child, the opportunity to refuse further use/collection, and the means to delete the child's PI;

ESRB-PC-12 · Parental access, review and deletion rights

User access rights are periodically reviewed and recertified by data and system owners with timely revocation of unneeded access.

IS-IV.B.4 · Access Reviews and Recertification
ISO 270431 control

Access review and recertification. Control from ISO 27043 framework, domain: ISO 27043: Access Control.

ISO27043-15 · Access review and recertification
ISO/SAE 214341 control

Access review and recertification. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Access Control.

ISO21434-15 · Access review and recertification

Questions people ask about access review

What is Access Review?
A periodic evaluation of user access rights and permissions to verify they remain appropriate, required by most compliance frameworks.
Why is Access Review important for compliance?
Access Review is a key concept in Information Security. Understanding access review helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Access Review?
Access Review appears in the requirement text of SOC 1 (SSAE 18 / ISAE 3402), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, ESRB Privacy Certified, FFIEC IT Examination Handbook, ISO 27043. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Access Review?
Explore our compliance framework pages to see how access review applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Access Review applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.