Access review

A periodic and event-driven check, usually signed off by the person accountable for the access, that each account and privilege is still needed, with anything unjustified removed.

An access review, also called recertification, confirms that every account and every privilege still has a current business justification, and removes those that do not. NIST SP 800-53 Rev. 5 expects accounts to be reviewed for compliance with account management requirements at an organisation-defined frequency (AC-2 j) and privileges to be reviewed for continued need (AC-6(7)). The ISC2 exam outline, under 5.5, gives user, system and service accounts as examples of what an account access review covers.

The reviewer should be the person accountable for the access, commonly the line manager or the system or data owner, not only the administrator. It is the detective partner to provisioning and deprovisioning: it finds privilege creep left behind by transfers, orphaned accounts left behind by leavers, and service accounts that nobody owns. Events such as a role change or an incident can also trigger one. A review in which every line is approved by default produces a record, not a control, because nothing is ever removed.

Exam relevance: a scenario is likely to describe accumulated access or a forgotten account and ask which control would have found it. Candidates are expected to name the access review, to place ownership with the accountable manager or owner, and to remember that service and system accounts are in scope even though no person leaves.