ACC-02Identity and Access
Access reviewed on a cadence
Entitlements are reviewed by someone who can judge them, with revocations tracked to completion.
Why it exists
A review that produces no revocations was not a review.
What usually proves it
Review packs, reviewer decisions, revocation evidence, completeness statement.
Smaller organizations
Quarterly, one reviewer per system, evidence kept.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC6.3
- Fully addressedISO/IEC 27001 Annex A · A.5.18
- Fully addressedNIST Cybersecurity Framework · PR.AA-05
- Fully addressedPCI DSS · 7.2.4
- Fully addressedHIPAA Security Rule · 164.308(a)(4)(ii)(C)
- Partially addressedGDPR · Art. 32 — Implied by appropriate measures.
- Deliberately absentEU AI Act — Not addressed.
- Deliberately absentNIST AI Risk Management Framework — Not addressed at control level.