SRS-085 Conduct periodic access reviews to verify permissions align with job functions.
Identifier​
SRS-085
Software System​
- Authentication Service
Category​
- Security
Description​
To enforce the principle of least privilege and mitigate the risk of "privilege creep," the system must provide functionality to conduct periodic access reviews. As users change roles and responsibilities, their access rights must be re-evaluated. The system shall provide tools for authorized administrators or managers to review the permissions assigned to users. This process must allow reviewers to easily see which permissions are granted to each user and verify that they align with their current job function. The system must also facilitate the modification or revocation of any permissions deemed excessive or unnecessary based on the review's findings.
Derived from PRS​
PRS-9F2
: Cybersecurity & continuous threat detection