UK NCSC Cyber Assessment Framework
Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework

UK NCSC Cyber Assessment Framework B2.d: B2.d Identity and access management

Identity and access for users, devices and systems are closely managed. Partially achieved: a robust procedure issues minimum access rights, reviewed regularly and through joiner-mover-leaver processes, and all access is logged and monitored. Achieved: the procedure is regularly audited, rights are reviewed at least annually and on role change, access logs are correlated with other records and expected activity, and unauthorised connection attempts raise alerts that are promptly investigated.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.