ctl-001
Privileged accounts are reviewed and recertified quarterly.
- Type
- DETECTIVE
- Automation
- SEMI_AUTOMATED
- Frequency
- QUARTERLY
- Owner
- Identity Engineering
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
- 1.Obtain and read the privileged access review procedure; confirm it defines scope, reviewer independence, recertification frequency, and remediation timelines.PR.AA-05
- 2.Confirm the privileged-account population is system-generated from authoritative identity sources rather than a manually maintained list.PR.AA-01
- 3.Walk through one completed quarterly review end to end to confirm the control operates as designed.
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
- 1.Select 25 privileged accounts across the period and confirm each was included in a completed recertification.
- 2.For each sampled account, verify an independent reviewer approved continued access with evidence retained.PR.AA-05
- 3.Confirm accounts flagged for removal were deprovisioned within the defined SLA.PR.AA-01
- 4.Verify late or missed recertifications were escalated and tracked to closure.
Linked risks
- Privileged access misusemitigation 3
Framework mappings & latest test
IAM-08IAM-10
Latest test:FAIL2026-03-31