Delete or disable any dormant accounts after a period of 45 days of inactivity, where supported.
Data system owner determines the access roles to the system in relation to the tasks of users. The compliance of the actual access rights with the planned ones must be monitored and the rights reassessed at regular intervals.
When reviewing access rights, care must also be taken to minimize admin rights and eliminate unnecessary accounts.
The organization has instituted automatic account monitoring and deactivation processes with a 45-day inactivity threshold, complemented by regular reviews and user notifications prior to deactivation, ensuring effective account management and security policy adherence.