# Authorisation Procedure (Joiner/Mover/Leaver and Recertification) | Document information | Value | |-----------------------|------| | Document type | Procedure instruction (VA-03) | | Scope | {{ISMS_SCOPE}} | | Organisation | {{ORG_NAME}} | | Process owner | {{ROLE_IT_LEAD}} | | Approved by | {{ROLE_ISB}} | | Version | {{DOC_VERSION}} | | Date | {{DOC_DATE}} | | Status | {{DOC_STATUS}} | ## 1. Purpose This procedure governs the request, approval, modification, revocation and regular review of access rights. It operationalises the associated policy ({{LINK:R08}}). ## 2. Scope Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}). ## 3. Trigger Joining, role change or leaving of a person; authorisation request; due recertification. ## 4. Inputs - HR notification - Role/rights catalogue (RBAC) - Existing authorisations from the central directory ({{TOOL_IAM}}) ## 5. Process 1. Record the request: request access/right in {{TOOL_TICKET}} (joiner/mover). 2. Business approval: check the necessity according to the least-privilege principle and approve. 3. Implementation: set rights on a role basis in the central directory ({{TOOL_IAM}}). 4. Leaver/change: upon leaving/change, revoke/adjust rights without delay. 5. Recertification ({{RECERT_FREQ}}, BL-IAM-05): owners confirm/revoke rights. 6. Privileged accounts: review and log separately (BL-IAM-06). ## 6. RACI | # | Step | R (Execution) | A (Accountable) | C (Consulted) | I (Informed) | |---|---------|------------------|------------------|-----------------|----------------| | 1 | Record the request | Manager/business unit | {{ROLE_IT_LEAD}} | - | - | | 2 | Business approval | Business unit/data owner | Business unit/data owner | {{ROLE_ISB}} | - | | 3 | Implementation | {{ROLE_IT_LEAD}} | {{ROLE_IT_LEAD}} | - | Requester | | 4 | Leaver/change | {{ROLE_IT_LEAD}} | {{ROLE_HR_LEAD}} | - | - | | 5 | Recertification ({{RECERT_FREQ}}, BL-IAM-05) | Business unit/data owner | {{ROLE_ISB}} | {{ROLE_IT_LEAD}} | - | | 6 | Privileged accounts | {{ROLE_IT_LEAD}} | {{ROLE_ISB}} | - | - | ## 7. Result & evidence Documented requests/approvals in {{TOOL_TICKET}}; current authorisation status in the central directory ({{TOOL_IAM}}); recertification evidence. Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}). ## 8. Key performance indicators (KPI) - Share of leaver rights revoked on time - Recertification rate - Number of orphaned/privileged accounts ## 9. Related documents - Associated policy: {{LINK:R08}} - {{LINK:VA-01}} - Technical security baseline: {{LINK:BASELINE}} - ISA mapping matrix: {{LINK:ISA_MAPPING}}