Control · ACC-03
Privileged access is just-in-time and reviewed
Access ControlSOC 2 · ISO 27001 · ITGC · RBIRisk High
Requirement to validation
Requirement
ISO-A.8.2 · ITGC-AM-02 · RBI-CSF-NBFC-Annex-1-2 · RBI-ITGRCA-2023-7.1 · SOC2-CC6.1 · SOC2-CC6.3
mapped
Policy
Access Control Policy
pol-access
Control
ACC-03
Privileged access is just-in-time and reviewed
Application
Amazon Web Services (ap-south-1) · Microsoft Entra ID · SAP S/4HANA
mapped
Evidence · Q3
7 items
3 approved · 4 pending · 0 rejected
Test · Q3
Fail
TST-ITGC-ACC-03 · Medium confidence
Finding
F-ITGC-02 · Medium
In Progress
Action
Rahul Nair
REM-F-ITGC-02 · In Progress
Validation
Pending
as recorded
What should be true
Administrative access to AWS, Azure, Entra ID and SAP is granted just-in-time through PIM / firefighter IDs with approval, MFA and session logging; no standing admin access exists outside break-glass accounts.
- Requirements
- ISO-A.8.2 A.8.2 · Privileged access rightsITGC-AM-02 ITGC-AM-02 · Privileged / superuser access is restricted and monitoredRBI-CSF-NBFC-Annex-1-2 RBI-CSF-NBFC Annex 1 §2 · Cyber security — SOC monitoring, vulnerability management, incident reporting (RBI Cyber Security Framework for NBFCs (IT Framework for the NBFC Sector))RBI-ITGRCA-2023-7.1 RBI-ITGRCA-2023 §7.1 · Access control — least privilege, privileged access management, periodic review (RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023)SOC2-CC6.1 CC6.1 · Logical access security software, infrastructure and architecturesSOC2-CC6.3 CC6.3 · Role-based access, least privilege and segregation of duties; access modification and removal
- Third parties
- —
- Testing procedure
- Entra PIM, AWS IAM Identity Center temporary elevation (TEAM), SAP GRC firefighter. Tests: Microsoft Entra ID: No permanent Global Administrator assignments; Amazon Web Services (ap-south-1): No standing AdministratorAccess permission sets; SAP S/4HANA: Firefighter sessions reviewed. Frequency continuous.
Findings (3)
| Finding | Observation | Control | Applications | Severity | Status | Owner | Action | Validation |
|---|---|---|---|---|---|---|---|---|
| F-ITGC-02 | Standing privileged access in production AWS | ACC-03 | Amazon Web Services (ap-south-1), Microsoft Entra ID, SAP S/4HANA | Medium | In Progress | Rahul Nair | REM-F-ITGC-02 · In Progress | Pending |
| F-IAQ2-ACC-03 | Standing privileged access in Entra and AWS | ACC-03 | Amazon Web Services (ap-south-1), Microsoft Entra ID, SAP S/4HANA | High | Closed | Ananya Rao | REM-F-IAQ2-ACC-03 · Closed | Failed |
| F-RBI-05 | Privileged access to production previously standing (MD-ITGRCA §7.1) | ACC-03 | Amazon Web Services (ap-south-1), Microsoft Entra ID, SAP S/4HANA | Medium | Closed | Ananya Rao | REM-F-RBI-05 · Closed | Validated |
Evidence (9)
| Evidence | Title | Control | Source system | Collected | Status |
|---|---|---|---|---|---|
| ITGC-REQ-004 | Microsoft Entra ID: No permanent Global Administrator assignments | ACC-03 | Microsoft Entra ID | 8 Oct 2026 | Accepted |
| ITGC-REQ-005 | AWS: No standing AdministratorAccess permission sets | ACC-03 | 7 Oct 2026 | Accepted | |
| ITGC-REQ-006 | SAP S/4HANA: Firefighter sessions reviewed | ACC-03 | SAP S/4HANA | 6 Oct 2026 | Accepted |
| Q2-EV-005 | Microsoft Entra ID · access review (Q2) | ACC-03 | Microsoft Entra ID | 4 Jun 2026 | Rejected |
| Q2-EV-006 | Amazon Web Services (ap-south-1) · policy document (Q2) | ACC-03 | Amazon Web Services (ap-south-1) | 9 Jun 2026 | Rejected |
| RBI-REQ-006 | Microsoft Entra ID: No permanent Global Administrator assignments | ACC-03 | Microsoft Entra ID | 6 Oct 2026 | Under review |
| RBI-REQ-007 | AWS: No standing AdministratorAccess permission sets | ACC-03 | 5 Oct 2026 | Under review | |
| SOC2-REQ-008 | AWS: No standing AdministratorAccess permission sets | ACC-03 | 6 Oct 2026 | Under review | |
| SOC2-REQ-009 | SAP S/4HANA: Firefighter sessions reviewed | ACC-03 | SAP S/4HANA | 5 Oct 2026 | Under review |
Tests (2)
| Test | Control | Cycle | Tested | By | Result | Confidence |
|---|---|---|---|---|---|---|
| TST-ITGC-ACC-03 | ACC-03 · Privileged access is just-in-time and reviewed | Q3 2026 Unified Program Review | 2 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit | Fail | Medium |
| TST-Q2-ACC-03 | ACC-03 · Privileged access is just-in-time and reviewed | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |