NIS2 Article 21(2)(i) and ISO 27001 A.5.18 expect you to check regularly who has access to your systems and to remove what is no longer needed. Access reviews guide a reviewer through that check, one account at a time, and keep the result as proof. Reviews are numbered AR-1, AR-2 and so on.
How to start a review (owners and admins)
- In your organization, open Access reviews in the menu and click Start a review.
- Enter a Title and the System or application, and link an Asset if you keep one for it.
- Choose the Reviewer and a Due date, then click Save review. The reviewer can open this review and decide on the accounts even without access to the whole register.
How to review the accounts (reviewer)
- Open the review. Reviewers who are members find it in their Tasks.
- Under Accounts, use Paste accounts to paste the list exported from the system: one account per line, with the access after a semicolon or a tab, for example "anna@example.com; Administrator". Or use Add this organization's members.
- For each account choose Keep, Change or Remove, add a Note if useful, and click Save decisions. Keep all undecided saves time when most accounts are fine.
- When every account is decided, click Complete review and add a Conclusion.
Completing locks the decisions. CloudSignLab does not change the system for you: carry out the changes and removals in the system itself.
Tips
- A review can hold up to 500 accounts.
- Open reviews appear in the reviewer's Tasks and get a reminder once they are overdue.
- Only owners and admins can cancel a review.
- Account names are never written to the audit log; it records only counts and decisions.
- Members do not see the Access reviews menu; they only open reviews given to them.
- Access reviews are included from the Professional package; your package may limit the number of reviews.