AM-06 Access Management

User Access Provisioning

Access is granted only on a documented, authorised, least-privilege basis.

Domain
Access Management
Control type
Preventive
Automated / manual
Manual
Frequency
Per event
Framework reference
COBIT DSS05.04; MAS TRM – Access

What good looks like

New-user access is requested via ticket, approved by line manager and system/data owner before provisioning; entitlements match the approved role.

Risk if it fails

Unauthorised or excessive access; SoD conflicts; data leakage.

How Tess tests it

5 tests — each concludes only on cited evidence.

Access-request workflow is mandatory

Design
Procedure
Inspect the provisioning workflow for a control gate.
Expected
No path to provision access without a logged request.
Sample
1 (design inspection)
Evidence
Access request tickets, approvals, HR new-hire list, entitlement extract.

Approval authority matrix is defined

Design
Procedure
Inspect the matrix mapping system/role to required approver(s).
Expected
Matrix is current and approved.
Sample
1 (design inspection)
Evidence
Access request tickets, approvals, HR new-hire list, entitlement extract.

Request raised before access granted

Operating
Procedure
For each sampled joiner, compare request date to account-creation date.
Expected
Request consistently precedes provisioning.
Sample
Judgmental, by population (e.g. 10–25)
Evidence
Access request tickets, approvals, HR new-hire list, entitlement extract.

Manager and owner approvals obtained

Operating
Procedure
Inspect approvals on each sampled request.
Expected
All required approvals present and from authorised approvers.
Sample
Judgmental, by population (e.g. 10–25)
Evidence
Access request tickets, approvals, HR new-hire list, entitlement extract.

Entitlements match approved request

Operating
Procedure
Reconcile granted entitlements to the request and role profile.
Expected
No access granted beyond what was approved.
Sample
Judgmental, by population (e.g. 10–25)
Evidence
Access request tickets, approvals, HR new-hire list, entitlement extract.

Evidence Tess looks for

Access request tickets, approvals, HR new-hire list, entitlement extract.

More in Access Management

Want Tess to test AM-06 against your evidence?

Book a demo