AM-06 Access Management
User Access Provisioning
Access is granted only on a documented, authorised, least-privilege basis.
- Domain
- Access Management
- Control type
- Preventive
- Automated / manual
- Manual
- Frequency
- Per event
- Framework reference
- COBIT DSS05.04; MAS TRM – Access
What good looks like
New-user access is requested via ticket, approved by line manager and system/data owner before provisioning; entitlements match the approved role.
Risk if it fails
Unauthorised or excessive access; SoD conflicts; data leakage.
How Tess tests it
5 tests — each concludes only on cited evidence.
Access-request workflow is mandatory
Design- Procedure
- Inspect the provisioning workflow for a control gate.
- Expected
- No path to provision access without a logged request.
- Sample
- 1 (design inspection)
- Evidence
- Access request tickets, approvals, HR new-hire list, entitlement extract.
Approval authority matrix is defined
Design- Procedure
- Inspect the matrix mapping system/role to required approver(s).
- Expected
- Matrix is current and approved.
- Sample
- 1 (design inspection)
- Evidence
- Access request tickets, approvals, HR new-hire list, entitlement extract.
Request raised before access granted
Operating- Procedure
- For each sampled joiner, compare request date to account-creation date.
- Expected
- Request consistently precedes provisioning.
- Sample
- Judgmental, by population (e.g. 10–25)
- Evidence
- Access request tickets, approvals, HR new-hire list, entitlement extract.
Manager and owner approvals obtained
Operating- Procedure
- Inspect approvals on each sampled request.
- Expected
- All required approvals present and from authorised approvers.
- Sample
- Judgmental, by population (e.g. 10–25)
- Evidence
- Access request tickets, approvals, HR new-hire list, entitlement extract.
Entitlements match approved request
Operating- Procedure
- Reconcile granted entitlements to the request and role profile.
- Expected
- No access granted beyond what was approved.
- Sample
- Judgmental, by population (e.g. 10–25)
- Evidence
- Access request tickets, approvals, HR new-hire list, entitlement extract.
Evidence Tess looks for
Access request tickets, approvals, HR new-hire list, entitlement extract.
More in Access Management
Want Tess to test AM-06 against your evidence?
Book a demo