GlossarySecurity awareness

Access review

Short answer

An access review is a periodic check in which managers or system owners confirm that each person's access to systems and data is still needed and appropriate, and remove what is not. It catches accounts and permissions that accumulate over time.

Why access drifts

People change roles and keep old permissions, projects end but access remains, contractors leave without their accounts being disabled, and administrators grant broad rights to solve a problem quickly. Without regular reviews, access only grows, and so does the damage a compromised account or an insider can do.

How it works

For each important system, a list of users and permissions is sent to the person who can judge it, usually the system owner or the user's manager. They confirm, adjust or revoke each access, the changes are applied, and the result is recorded with dates and approvals. Privileged accounts are reviewed more often, typically every quarter; other access every six or twelve months, depending on risk.

Making it manageable

Centralising access through SSO and an identity provider reduces the number of places to check. Role based access, part of IAM, means reviewing roles instead of individual permissions. Many identity and compliance platforms automate the review campaigns and keep the evidence.

Where it shows up in compliance

ISO 27001 requires access rights to be reviewed at planned intervals (Annex A 5.18), and SOC 2, the ENS and NIS2 expect the same. Access reviews are among the most requested pieces of evidence in audits, and gaps here are a frequent finding. Privileged access is covered in more depth under PAM.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub