Knowella

System Access Review

Reviews who has access to which systems and at what privilege level. Run every six months. Carried out by IT with system owners. Leavers who still have access and administrators nobody remembers appointing are the usual findings.

KnowComplyReviewCMP-036
Completed by
Carried out by IT with system owners
Raised
At the review interval, and after any trigger event

Summary

In short

  • A system access review is a review used in KnowComply that reviews who has access to which systems and at what privilege level. It is built against ISO 27001 cl.9.2 and forms part of the Data Protection and Information Security programme.
  • Run every six months. Carried out by IT with system owners.
  • The template holds 48 fields across 6 sections.
  • Scoring is unjustified access, where low is good.
  • ISO 27001 is information security management systems. The international standard for protecting information confidentiality, integrity and availability. Certifiable.
  • It connects to the rest of the library: links Offboarding, Access control.

What it is

What it is

What is a system access review?

A system access review is a review used in KnowComply that reviews who has access to which systems and at what privilege level. It is built against ISO 27001 cl.9.2 and forms part of the Data Protection and Information Security programme.

When is a system access review completed?

A system access review is completed at the review interval, and after any trigger event. Run every six months.

When to use it

When to use it, and when not to

This review is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.

Use it for

  • The event or activity this review covers has occurred, or is about to
  • The workspace is being set up, or the register needs an entry added or retired
  • You are running the Data Protection and Information Security programme and this is one of its steps
  • A linked record needs this one to exist: links offboarding, access control

Not for

  • Information Security Risk Assessment, which assesses threats to systems, data and operational technology, including plant control systems.
  • Cyber Incident Record, which records a cyber event affecting systems, data or plant operation, with containment, recovery and notification.
  • Backup and Recovery Test Record, which records a test that backups can actually be restored, not merely that they ran.
  • Anything outside KnowComply, which belongs in the workspace that owns that process

Standards

What it is built against

ISO 27001Information security management systems

The international standard for protecting information confidentiality, integrity and availability. Certifiable.

ISOInternational Organization for Standardization

A voluntary international standard. Widely adopted, often required by customers, and certifiable where a management system standard.

FAQ

Frequently asked questions

What is the system access review template based on?+

It is built against ISO 27001 cl.9.2. ISO 27001 is information security management systems. The international standard for protecting information confidentiality, integrity and availability. Certifiable. ISO is international Organization for Standardization. A voluntary international standard. Widely adopted, often required by customers, and certifiable where a management system standard.

What sections does the system access review contain?+

There are 6 sections: header, process, findings, action, related records, outcome. Together they hold 48 fields, 43 of which are required.

How many system access review records should we have?+

This is a singleton. One record per workspace, set up once and maintained, rather than one per event. Other templates refer back to it.

Which programme does the system access review belong to?+

It is part of Data Protection and Information Security. Monitoring introduced with consultation, and backups proven by restoring them.

How is a system access review scored?+

Scoring is unjustified access. Low is good. Scores exist to make the form tell you something, not to produce a percentage for its own sake.

Can the system access review template be changed?+

Yes. Every field, option, score and conditional rule is editable, and the links to other templates come with it. Most teams install it as it is, run it for a cycle, then adjust.

The agents

What the agents do with it

The form is the easy part. Keeping it current, routing it to the right owner and holding the evidence together is the work that actually slips.

KnowComply

Holds the system access review library against your registers, routes each record to its owner, and keeps the evidence trail together.

Ella

Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.

This template lives in KnowComplyaudit and governance. Audit programmes, legal register, management review, risk and certification.

Sources

Sources

  • ISO 27001 — Information security management systems
  • ISO — International Organization for Standardization
Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.