Information Security Management

Access Provisioning and Offboarding

Access is granted by role from a documented baseline once onboarding is complete, and requires approval from the system owner for anything touching production. On a role change, access is reviewed and anything no longer needed is removed. On termination, a documented clearance process revokes system and premises access and recovers company property, and corporate accounts are disabled the same business day. Access permissions are recertified on a regular cycle.

How it is checked

A documented termination clearance process tracked in our internal IT ticket system, and periodic recertification of access permissions.

Framework requirements this speaks to

  • ISO 27001 A.5.18 (access rights)
  • ISO 27001 A.6.5 (responsibilities after termination or change of employment)
  • SOC 2 Common Criteria - Logical Access

Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.

Need the evidence behind this?

Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.