Continuous ISO 27001 access control review in Australia
Access control is one of the first areas an ISO 27001 auditor examines because it connects policy, technology, people and business risk. A written rule saying that permissions must be reviewed is not enough. An organisation needs to show who reviewed access, what they examined, which exceptions were found, who approved changes and whether those changes were completed.
Traditional reviews often happen quarterly or before an audit. That approach can leave a long period in which former employees retain accounts, contractors keep unnecessary privileges or production access expands without clear ownership. Continuous compliance changes the rhythm by checking relevant signals throughout the year and retaining evidence as work happens.
For Australian organisations, this matters in a market where buyers increasingly request security assurance during procurement. A software company selling to a bank in Sydney, a health provider in Melbourne or a government supplier in Canberra may need to demonstrate reliable identity governance before the contract is signed. ISO 27001 evidence can therefore support revenue as well as risk management.
The approach also needs to fit Australian privacy and employment expectations. The Privacy Act 1988 and Australian Privacy Principles influence how organisations collect and use workforce data, while APRA-regulated entities may have additional obligations under CPS 234. Continuous assurance should monitor access responsibly, with clear purpose, limited data collection and appropriate retention.
Why access reviews need continuous assurance
Access rights change whenever people join, leave, change roles or work on new projects. Cloud services, source repositories, ticketing systems and data platforms can create additional privileges through automated provisioning. A quarterly review may confirm the situation on one date while missing a significant change made the following week.
A continuous model watches for events that should trigger review. These may include a privileged role assignment, an inactive account becoming active, a contractor’s engagement reaching its end date, a change to a production group or a separation recorded in the human resources system. The goal is not to ask managers to approve every login. It is to route meaningful changes to the right owner.
This creates a closer relationship between the access control policy and operational behaviour. If the policy requires least privilege, the system can identify users with excessive permissions. If it requires prompt removal after termination, an integration can compare the HR departure record with identity provider status. If it requires periodic certification, the platform can open review tasks and preserve the resulting decision.
What ISO 27001 expects from the review process
ISO 27001:2022 Annex A includes controls for access control, identity management, authentication information and access rights. Controls 5.15 through 5.18 are especially relevant to review programmes. They are intended to help an organisation establish rules, manage identities, protect authentication information and review access rights throughout the information lifecycle.
The standard does not prescribe one universal review interval. Frequency should reflect risk, system sensitivity, user population and the speed of change. Administrative access to a production environment may need event-based and monthly review, while access to a low-risk internal application might be reviewed quarterly. The rationale should be recorded in the risk treatment and control documentation.
A strong review record answers several practical questions. Which system or data set was covered? What population was included? Who was accountable for each decision? Were dormant, duplicate or excessive accounts identified? What remediation was requested? When was it completed, and who verified completion? These details turn an approval email into defensible audit evidence.
Evidence should also demonstrate exceptions. An emergency account, shared service identity or temporary vendor privilege may be legitimate, but it needs an owner, business justification, expiry date and compensating controls. A continuous compliance platform can flag missing fields and prevent an exception from quietly becoming permanent.
How continuous compliance turns policy into evidence
The process begins by translating policy language into control tests. “Access is reviewed regularly” can become a test that checks whether every in-scope application has an assigned owner and whether each review was completed within its defined interval. “Privileged access is restricted” can become a test for membership in administrator groups, approval records and use of just-in-time elevation.
Integrations then connect the control to operational systems. Typical sources include Microsoft Entra ID or another identity provider, HR platforms, cloud consoles, endpoint tools, Git repositories, ticketing systems and privileged access management services. The platform does not need to replace these systems. It needs to collect reliable signals, compare them with approved policy and create an accountable workflow when conditions do not match.
Automation is valuable because it keeps evidence current. A completed review can be linked to the users and entitlements considered at that time. A remediation ticket can include the affected account, policy requirement, owner, due date and closure evidence. For a broader example of preserving test records around security operations, organisations can review this incident response evidence guide.
Continuous assurance should still include human judgement. A manager may know that a developer needs short-term production access for a release, or that a service account supports a critical integration. Automation identifies the condition and structures the decision; accountable people determine whether the access is justified.
Comparing review methods and evidence quality
Different review models create different levels of assurance. A spreadsheet can be suitable for a small environment with few applications, but it becomes difficult to maintain as identities, contractors and cloud services multiply. The important distinction is whether an organisation can show a consistent link between policy, current data, approval and remediation.
| Review approach | Typical trigger | Evidence produced | Common weakness |
|---|---|---|---|
| Annual manual review | Audit preparation or policy calendar | Signed spreadsheet or email approval | Long gaps between checks and weak remediation tracking |
| Quarterly certification | Fixed review cycle | Manager attestations and access lists | Can miss fast changes between cycles |
| Event-based automation | Joiner, mover, leaver or privilege change | Trigger, decision, ticket and closure record | Requires reliable integrations and ownership |
| Continuous compliance | Events plus scheduled control tests | Time-stamped control status and linked evidence | Needs careful scoping to avoid alert fatigue |
| Risk-based hybrid model | System sensitivity and change rate | Review rationale, exceptions and targeted attestations | Requires mature risk classification |
For many Australian businesses, a hybrid model is practical. High-risk systems can use event-driven checks and frequent certifications, while less sensitive applications follow a quarterly schedule. The method should be documented in the statement of applicability, internal procedures and system ownership records.
The quality of evidence matters as much as its volume. Thousands of raw log entries may be less useful than a concise record showing that a privileged access change was detected, assessed, approved or rejected, remediated and independently verified. Auditors need traceability, not an uncontrolled export from every connected system.
Designing workflows for Australian organisations
A useful workflow starts with an inventory of applications and data owners. In a hybrid organisation with teams across Sydney, Melbourne, Brisbane and Perth, ownership cannot depend on informal office knowledge. Each system should have a named accountable owner, a backup approver and a defined classification that explains the expected review frequency.
The workflow should distinguish employees, contractors, service providers and non-human identities. Australian businesses often rely on external developers, managed service providers and offshore support teams. Their access should have a business sponsor, contractual basis, minimum required permissions and an expiry or review date. A contractor’s access should not remain active simply because a project manager forgot to close a ticket.
Privacy must be designed into monitoring. Access reviews may reveal employment status, work patterns, team structures or activity histories. The organisation should collect only information required for the control, restrict who can view it and set retention periods. Guidance on workplace monitoring limits can provide useful context when designing employee-related monitoring, although the organisation should obtain advice suited to Australian law and its specific workplace arrangements.
Regulated organisations need to connect access reviews with broader resilience and security obligations. A financial entity may need evidence aligned with APRA expectations, while a healthcare provider must consider sensitive health information and the relevant state or territory environment. These requirements do not replace ISO 27001, but they can influence risk ratings, approval levels and evidence retention.
Practical recommendations for implementation
A phased programme is usually easier to operate than an attempt to connect every application at once. Begin with identity providers, privileged accounts and systems holding regulated or commercially sensitive information. Establish ownership and baseline access before adding sophisticated automation.
- Define review frequency by system risk, privilege level, user type and rate of change.
- Connect joiner, mover and leaver events to identity workflows and remediation tickets.
- Require business justification, owner, expiry date and approval for exceptions.
- Preserve the reviewed population, decision, timestamp and remediation outcome as evidence.
- Test the workflow with sample terminations, privilege changes and overdue reviews.
The control should have a clear escalation path. An overdue manager certification may first generate a reminder, then go to the system owner and security team, and finally become a formal exception. High-risk conditions, such as an inactive privileged account or terminated user with production access, may need immediate response rather than a routine reminder.
The Secured Buy program can help product and security teams connect governance controls with development and operational workflows. This is particularly useful when access changes occur through infrastructure-as-code, CI/CD pipelines or automated cloud provisioning. A control that runs where the change is made is more likely to prevent non-compliant access than a control that discovers it weeks later.
How to measure audit readiness over time
Metrics should show whether the control works, rather than simply how many reviews were completed. Useful measures include the percentage of systems with named owners, time to remove leaver access, the number of overdue certifications, privileged accounts without current approval and the average age of open access exceptions.
Trend data helps distinguish isolated mistakes from structural problems. If leaver access is removed quickly but contractor access remains open for months, the weakness may sit in procurement or project offboarding. If managers repeatedly approve excessive permissions, role design or entitlement descriptions may be unclear. Continuous assurance makes these patterns visible before an audit interview exposes them.
Organisations should also test the evidence itself. Select a sample of completed reviews and trace each one from the original identity or entitlement data through the approval decision and final remediation. Check whether timestamps are reliable, whether records can be exported and whether a reviewer unfamiliar with the system can understand what happened.
A mature programme produces an audit-ready evidence trail without a last-minute campaign. Policy requirements remain visible, control owners receive targeted tasks, exceptions have an end date and changes are assessed near the time they occur. That combination strengthens ISO 27001 conformity while giving Australian organisations a clearer, faster way to demonstrate trustworthy access governance to customers, regulators and internal leadership.