Control detail

Quarterly privileged access review

ctl-001 · DETECTIVE · QUARTERLY

ctl-001

Privileged accounts are reviewed and recertified quarterly.

Key control
Type
DETECTIVE
Automation
SEMI_AUTOMATED
Frequency
QUARTERLY
Owner
Identity Engineering

Control Design Assessment (CDA)

Procedures evaluating whether the control is designed adequately.

  1. 1.Obtain and read the privileged access review procedure; confirm it defines scope, reviewer independence, recertification frequency, and remediation timelines.PR.AA-05
  2. 2.Confirm the privileged-account population is system-generated from authoritative identity sources rather than a manually maintained list.PR.AA-01
  3. 3.Walk through one completed quarterly review end to end to confirm the control operates as designed.

Control Operating Effectiveness (COE)

Procedures evaluating whether the control operated over the testing period.

  1. 1.Select 25 privileged accounts across the period and confirm each was included in a completed recertification.
  2. 2.For each sampled account, verify an independent reviewer approved continued access with evidence retained.PR.AA-05
  3. 3.Confirm accounts flagged for removal were deprovisioned within the defined SLA.PR.AA-01
  4. 4.Verify late or missed recertifications were escalated and tracked to closure.

Linked risks

  • Privileged access misusemitigation 3

Framework mappings & latest test

IAM-08IAM-10
Latest test:FAIL2026-03-31