Sekit CSF · Family
Identity & Access Management
30 controls in 10 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0085Access reviews (recertification)no mappings yetAccess rights are formally reviewed periodically to confirm they remain appropriateRCF-0061Identity lifecycleno mappings yetUser accounts are formally managed from creation to deletion across all systemsRCF-0088JML (joiner-mover-leaver)no mappings yetA formal process covers access management for joiners, movers and leaversRCF-0067Least privilege / RBACno mappings yetUsers only have access to what their role requiresRCF-0076Password policyno mappings yetStrong password requirements are formally defined and communicatedRCF-0070Privileged access managementno mappings yetAdministrator accounts are strictly controlled and separated from regular accountsRCF-0082Remote accessno mappings yetClear rules govern how employees access company systems remotelyRCF-0079Session managementno mappings yetInactive sessions are formally required to terminate after a defined periodRCF-0073SSO & federationno mappings yetA centralised identity system allows secure access to all applications with one loginRCF-0064Strong authentication (MFA)no mappings yetA second verification step beyond password is required to access critical systems
Process
RCF-0086Access reviews (recertification)no mappings yetManagers regularly confirm their team has the correct level of accessRCF-0062Identity lifecycleno mappings yetThere is a consistent process for onboarding and offboarding user accessRCF-0089JML (joiner-mover-leaver)no mappings yetHR and IT coordinate promptly when employment status changesRCF-0068Least privilege / RBACno mappings yetAccess rights are adjusted when roles change and removed when no longer neededRCF-0077Password policyno mappings yetEmployees consistently use a password manager and follow password hygieneRCF-0071Privileged access managementno mappings yetPrivileged access is logged, time-limited and formally approvedRCF-0083Remote accessno mappings yetRemote access is consistently configured securely and employees are trainedRCF-0080Session managementno mappings yetUsers consistently lock screens and log out when leaving their workstationRCF-0074SSO & federationno mappings yetNew applications are integrated with the central identity system before deploymentRCF-0065Strong authentication (MFA)no mappings yetMFA is consistently applied with no informal exceptions
Technical
RCF-0087Access reviews (recertification)no mappings yetSystems automatically generate access reports to support periodic reviewsRCF-0063Identity lifecycleno mappings yetAccount lifecycle is technically enforced — access is removed automatically when someone leavesRCF-0090JML (joiner-mover-leaver)no mappings yetAccess provisioning and deprovisioning is automated through HR system integrationRCF-0069Least privilege / RBACno mappings yetPermissions are enforced at the system level not based on user behaviourRCF-0078Password policyno mappings yetStrong password requirements are technically enforced at the system levelRCF-0072Privileged access managementno mappings yetTechnical tools control and monitor all use of privileged accountsRCF-0084Remote accessno mappings yetRemote connections are encrypted and restricted to approved devices onlyRCF-0081Session managementno mappings yetScreen locks and session timeouts are technically enforced on all devicesRCF-0075SSO & federationno mappings yetAll critical applications authenticate through a central identity providerRCF-0066Strong authentication (MFA)no mappings yetMFA is technically enforced and cannot be bypassed
Ask Sekura: “What evidence proves Identity & Access Management?”
Connect your AI · free MCP
https://staging.sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.