How to answer
Are user access rights reviewed periodically?
Policies say quarterly. The reviewer is asking about the person who left in March, and periodic review is the wrong instrument for finding them.
Yes. Access to production systems is reviewed quarterly by the system owner. Access no longer required is revoked as part of the review, and departures are handled separately through offboarding within [one business day].
Square brackets are yours to fill in. FillTrust grades an answer like this implied, not stated when your documents support it.
- Answered from
- Your access control standard, which should name the cadence and the reviewer.
- Evidence to attach
- Occasionally the sign-off from the most recent review. Never the access list itself.
- Where it is asked
- CAIQ v4.0 · IAM-08SIG LiteISO 27001 Annex A · A.5.18
Answer this one honestly, because it is the control most likely to exist on paper and not in the calendar. "Access is reviewed quarterly" appears in almost every access control standard. A quarterly review that last happened ten months ago is the single most common finding in a first SOC 2 audit, and a reviewer asking a follow-up will ask for the date of the last one.
If your reviews are real, name the cadence, name who performs them, and name the date of the most recent. If they are not yet real, the answer that works is the one that says what you actually do: "access is reviewed on a rolling basis as part of onboarding and offboarding; a formal quarterly review is being introduced from [quarter]". A reviewer can price that risk, and they cannot price a claim that turns out to be aspirational.
There is a more useful thing to understand about this question, though: periodic review is not the control the reviewer is worried about. What worries them is the person who left the company in March and whose GitHub access is still live in September. A quarterly review would find that up to three months late. What actually addresses it is offboarding, and the strongest answer to this question mentions both: the periodic review as the backstop, and same-day revocation on departure as the primary control.
The other place these answers narrow too far is scope. Reviewing the identity provider is not reviewing access, because the things that are not behind it are exactly the risky ones: direct database credentials, the cloud provider root account, the third-party SaaS somebody bought on a company card, shared credentials in a password manager vault. A review that covers the identity provider and says so is honest. A review that covers the identity provider and is described as covering access is not.
How this one goes wrong
Specific to this question, not general advice.
- A policy that says quarterly and a last review that was ten months ago. This is the single most common finding in a first SOC 2 audit.
- Answering about the review and not about offboarding. A reviewer's real worry is the person who left in March, and periodic review is the wrong instrument for that.
- Reviewing the identity provider and forgetting everything not behind it: the database, the cloud console root, the third-party tools bought on a card.