ScopeThis assessment applies to systems that handle personal information.
Please assess the status of the following controls for access management of critical information systems.
1. Are access privileges granted based on the least-privilege principle?
2. Are granted privileges reviewed periodically and unnecessary privileges removed?
3. Are operations by privileged accounts logged and monitored?