ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Access Revocation Checklist

Access Revocation Checklist

1. Purpose

The Access Revocation Checklist ensures that user access to organizational information, systems, applications, cloud platforms, networks, and physical facilities is removed or adjusted when access is no longer required.

The objective is to prevent:

  • Unauthorized access after employment or engagement ends
  • Excessive or obsolete access
  • Continued privileged access
  • Unauthorized access to customer information
  • Continued access through forgotten accounts, tokens, or keys
  • Access remaining active after role changes
  • Security risks caused by dormant accounts

Key principle:

Identify → Review → Revoke → Verify → Record → Close


2. When to Use This Checklist

Use this checklist for:

  • Employee termination
  • Employee resignation
  • Contractor/consultant exit
  • Supplier personnel exit
  • Internal role change
  • Department transfer
  • Project completion
  • Temporary access expiry
  • Privilege reduction
  • Long-term leave where access must be suspended
  • Security incidents
  • Lost or compromised credentials
  • Administrative access changes
  • Emergency access termination

For high-risk or involuntary termination, access may need to be revoked immediately or before notification, according to the organization’s approved procedure.


3. Access Revocation Information

FieldDetails
Revocation ID
User Name
Employee/Contractor ID
Department / Supplier
Role
Manager / Business Owner
Access TypeEmployee / Contractor / Privileged / Temporary
Reason for RevocationExit / Transfer / Expiry / Security / Other
Effective Date
Effective Time
Requested By
Approved By
IT/Security Owner
Risk LevelLow / Medium / High / Critical
StatusOpen / In Progress / Completed

4. Access Revocation Process

Access Revocation Request
↓
Identify All User Access
↓
Determine Required Revocation
↓
Disable/Revoke Access
↓
Revoke Credentials, Tokens & Keys
↓
Review Privileged/Cloud Access
↓
Terminate Active Sessions Where Applicable
↓
Verify Revocation
↓
Update Access Records
↓
Retain Evidence
↓
Close Request


5. Identity and Authentication

RequirementCompletedEvidence / Remarks
Corporate user account disabled☐
Identity Provider account disabled☐
SSO access revoked☐
MFA methods removed☐
Recovery email reviewed☐
Recovery phone reviewed☐
Password reset where required☐
Active sessions terminated where applicable☐
Authentication tokens revoked☐
Personal access tokens revoked☐
Digital certificates revoked☐

6. Email and Collaboration Access

Verify access to:

  • ☐ Corporate email
  • ☐ Shared mailboxes
  • ☐ Distribution groups
  • ☐ Microsoft 365 / Google Workspace
  • ☐ Teams / Slack
  • ☐ SharePoint / Google Drive
  • ☐ Confluence
  • ☐ Collaboration platforms
  • ☐ Customer communication platforms

Check:

  • ☐ User account disabled
  • ☐ Group memberships removed
  • ☐ Shared mailbox permissions removed
  • ☐ Delegated access removed
  • ☐ Email forwarding reviewed
  • ☐ External forwarding disabled where required
  • ☐ Shared documents reviewed
  • ☐ Ownership transferred where required

7. VPN and Remote Access

  • ☐ VPN account disabled
  • ☐ VPN certificate revoked
  • ☐ Remote access permissions removed
  • ☐ Remote desktop access removed
  • ☐ Zero Trust/remote access permissions removed
  • ☐ Network access policies updated
  • ☐ Remote access sessions terminated where applicable
  • ☐ Remote administration access removed

8. SaaS Application Access

Review all applications associated with the user.

ApplicationAccess RemovedAdmin Access RemovedVerified By
CRM☐☐
HR System☐☐
Finance System☐☐
Project Management☐☐
Support Platform☐☐
Documentation Platform☐☐
Security Platform☐☐
Password Manager☐☐
Communication Platform☐☐
Other SaaS☐☐

Also verify:

  • ☐ Application-specific accounts disabled
  • ☐ Group memberships removed
  • ☐ Admin privileges removed
  • ☐ API tokens revoked
  • ☐ OAuth authorizations reviewed
  • ☐ Integrations owned by the user transferred
  • ☐ Customer-facing access removed

9. Source Code and Development Access

For developers and technical personnel:

  • ☐ GitHub/GitLab/Bitbucket access revoked
  • ☐ Repository access removed
  • ☐ Organization membership removed
  • ☐ Repository administrator access removed
  • ☐ Personal access tokens revoked
  • ☐ SSH keys removed
  • ☐ CI/CD access removed
  • ☐ Deployment permissions removed
  • ☐ Infrastructure-as-Code access removed
  • ☐ Package registry access removed
  • ☐ Code-signing access reviewed
  • ☐ Development environment access removed
  • ☐ Production access removed

10. AWS / Cloud Access

For AWS, Azure, GCP, or other cloud environments:

Access AreaRevokedVerified
Cloud SSO☐☐
IAM User☐☐
IAM Roles☐☐
Administrator Role☐☐
Production Account☐☐
Development Account☐☐
Database Access☐☐
S3/Object Storage☐☐
EC2/Compute☐☐
Kubernetes☐☐
CI/CD☐☐
Secrets Manager☐☐
Key Management☐☐
Network Administration☐☐
Security Tools☐☐

Verify

  • ☐ IAM access removed
  • ☐ Access keys disabled/revoked
  • ☐ IAM roles reviewed
  • ☐ Privileged roles removed
  • ☐ Temporary credentials addressed
  • ☐ SSH keys revoked
  • ☐ API credentials revoked
  • ☐ Cloud console access removed
  • ☐ Production access removed
  • ☐ Cloud security logs reviewed where required

11. Privileged Access

Privileged access requires additional verification.

Check:

  • ☐ Domain administrator access removed
  • ☐ Cloud administrator access removed
  • ☐ Database administrator access removed
  • ☐ Network administrator access removed
  • ☐ Security administrator access removed
  • ☐ Server administrator access removed
  • ☐ Application administrator access removed
  • ☐ Source-code administrator access removed
  • ☐ CI/CD administrator access removed
  • ☐ Backup administrator access removed
  • ☐ Password-manager administrator access removed
  • ☐ Privileged Access Management access removed

Privileged Credential Review

  • ☐ Shared administrator credentials reviewed
  • ☐ Credentials changed where required
  • ☐ Secrets accessible to user reviewed
  • ☐ API keys reviewed
  • ☐ SSH keys reviewed
  • ☐ Emergency/break-glass access reviewed
  • ☐ Relevant privileged activity reviewed where required

12. Database and Data Access

Review access to:

  • ☐ Production databases
  • ☐ Development databases
  • ☐ Test databases
  • ☐ Data warehouses
  • ☐ Analytics platforms
  • ☐ Customer data stores
  • ☐ File shares
  • ☐ Object storage
  • ☐ Backup repositories

Verify:

  • ☐ Database account disabled
  • ☐ Database roles removed
  • ☐ Direct access revoked
  • ☐ Read/write permissions removed
  • ☐ Export permissions removed
  • ☐ Administrative permissions removed
  • ☐ Data-sharing permissions removed

13. Security Tools

For security/IT personnel, review:

  • ☐ SIEM
  • ☐ EDR
  • ☐ Vulnerability management platform
  • ☐ Firewall
  • ☐ WAF
  • ☐ Cloud security platform
  • ☐ Security monitoring platform
  • ☐ Incident management platform
  • ☐ Password manager
  • ☐ Security ticketing system
  • ☐ Backup platform
  • ☐ Certificate management
  • ☐ Key management

Verify both normal and administrative access.


14. Physical Access

Where applicable:

  • ☐ Building access card disabled
  • ☐ Office access removed
  • ☐ Data center access removed
  • ☐ Restricted-area access removed
  • ☐ Physical keys returned
  • ☐ Security badge disabled
  • ☐ Visitor privileges removed
  • ☐ Physical security system access removed

15. Mobile and Device Access

Review:

  • ☐ Corporate laptop access
  • ☐ Corporate mobile
  • ☐ Tablet
  • ☐ MDM/MAM
  • ☐ Endpoint management
  • ☐ Device certificates
  • ☐ Corporate applications
  • ☐ VPN profiles
  • ☐ Wi-Fi certificates
  • ☐ Device-based authentication

For BYOD:

  • ☐ Corporate applications removed where applicable
  • ☐ Corporate account access revoked
  • ☐ Corporate certificates removed
  • ☐ VPN access removed
  • ☐ Organization data removed where authorized
  • ☐ Device management enrollment removed where applicable

16. API Keys, Tokens and Credentials

A common source of incomplete access revocation is failure to identify non-user credentials.

Review:

  • ☐ API keys
  • ☐ Personal access tokens
  • ☐ OAuth tokens
  • ☐ SSH keys
  • ☐ Cloud access keys
  • ☐ Service credentials
  • ☐ Database credentials
  • ☐ Certificates
  • ☐ Signing keys
  • ☐ CI/CD credentials
  • ☐ Automation credentials

Where credentials are shared or embedded:

  • ☐ Credential ownership identified
  • ☐ Credential rotated where required
  • ☐ Dependent systems tested
  • ☐ New credential securely distributed
  • ☐ Old credential disabled

17. Active Sessions

Where technically possible:

  • ☐ Web sessions terminated
  • ☐ VPN sessions terminated
  • ☐ Cloud console sessions terminated
  • ☐ SSO sessions terminated
  • ☐ Mobile sessions removed
  • ☐ SaaS sessions terminated
  • ☐ Remote desktop sessions terminated
  • ☐ API tokens invalidated

The exact capability depends on the system.


18. Role Change / Internal Transfer

Access revocation is also required when an employee changes roles.

Verify:

  • ☐ Previous role identified
  • ☐ Previous access reviewed
  • ☐ Access no longer required removed
  • ☐ New access separately approved
  • ☐ Privileged access reassessed
  • ☐ Group memberships updated
  • ☐ Cloud roles updated
  • ☐ SaaS permissions updated
  • ☐ Source-code permissions updated
  • ☐ Access review completed

Principle:

Do not simply add new access. Remove access that is no longer required.


19. Temporary Access Expiry

For temporary access:

FieldDetails
User
System
Access Granted
Expiry Date
Business Owner
Approval
Revocation Date
Verified By

Verify:

  • ☐ Expiry date reached
  • ☐ Access automatically expired where supported
  • ☐ Access manually revoked if necessary
  • ☐ Owner notified
  • ☐ Evidence retained

20. Emergency Access Revocation

Emergency revocation may be required for:

  • Compromised credentials
  • Suspected account compromise
  • Lost/stolen device
  • Security incident
  • Unauthorized access
  • Insider-risk event
  • Management-directed emergency termination

Immediate actions may include:

  • ☐ Disable account
  • ☐ Revoke sessions
  • ☐ Revoke MFA/token access
  • ☐ Revoke cloud access
  • ☐ Rotate credentials
  • ☐ Revoke API keys
  • ☐ Block VPN
  • ☐ Restrict network access
  • ☐ Preserve relevant logs
  • ☐ Escalate to incident management

Emergency actions should subsequently be documented and reviewed.


21. Access Revocation Verification

The person performing the revocation should not simply mark the checklist complete without evidence where evidence is available.

Verify:

  • ☐ Account shows disabled
  • ☐ Access groups removed
  • ☐ Privileged roles removed
  • ☐ Cloud roles removed
  • ☐ SaaS access removed
  • ☐ VPN access removed
  • ☐ Tokens/keys revoked
  • ☐ Physical access removed
  • ☐ Active sessions terminated where applicable
  • ☐ Access records updated
  • ☐ Required logs/evidence retained

22. Access Revocation Evidence

Examples of evidence include:

  • Identity Provider screenshot/report
  • IAM records
  • SSO logs
  • Access-management ticket
  • Application user status
  • AWS IAM evidence
  • VPN access records
  • GitHub/GitLab membership records
  • SaaS administration records
  • Token/key revocation records
  • MDM records
  • Physical access records
  • Security ticket
  • Approval record
  • Audit log
  • Completed checklist

Evidence should demonstrate what was revoked, when, and by whom, where applicable.


23. Exceptions

If access cannot be revoked immediately:

Exception IDSystemAccess RemainingReasonRiskCompensating ControlOwnerDue DateStatus

Exceptions should be formally approved and tracked to closure.


24. Final Access Revocation Record

ItemStatus
User identity disabled☐
SSO revoked☐
MFA removed☐
Email access removed☐
VPN removed☐
SaaS access removed☐
Source-code access removed☐
Cloud access removed☐
Privileged access removed☐
Database access removed☐
API tokens revoked☐
SSH keys revoked☐
Certificates revoked☐
Physical access removed☐
Device access addressed☐
Active sessions terminated☐
Business ownership transferred☐
Exceptions documented☐
Evidence retained☐
Final verification completed☐

25. Roles and Responsibilities

Manager / Business Owner

  • Request access revocation
  • Confirm reason and effective date
  • Identify systems and information accessed
  • Confirm business ownership transfer

IT

  • Disable accounts
  • Revoke technical access
  • Remove device/network access
  • Maintain access records

Security / ISMS

  • Review privileged and high-risk access
  • Coordinate emergency revocation
  • Review security implications
  • Verify evidence where required

System/Application Owner

  • Remove application-specific access
  • Remove privileged permissions
  • Confirm revocation

Cloud Administrator

  • Revoke cloud roles, keys, and permissions
  • Review production access
  • Maintain cloud evidence

HR / Supplier Owner

  • Coordinate employee/contractor exit
  • Confirm termination or engagement end
  • Notify relevant teams

26. Audit Sampling Approach

During an ISO 27001 audit, the organization may demonstrate effectiveness by selecting samples such as:

  • Recent employee exits
  • Recent contractor exits
  • Recent internal transfers
  • Recent privileged-access removals
  • Recently expired temporary access

For each sample, demonstrate:

Access Request / Exit Event
→ User/System Identified
→ Access Revoked
→ Verification
→ Evidence

This provides stronger evidence than simply showing an access-control policy.


27. Common Mistakes

1. Only disabling the email account

The user may still have cloud, SaaS, VPN, GitHub, or production access.

2. Forgetting API tokens

Tokens can remain active even after the primary account is disabled.

3. Forgetting SSH keys

Technical users may retain server or cloud access through SSH keys.

4. Not reviewing privileged access

Administrative access requires separate verification.

5. Adding new access without removing old access

Role changes can create excessive privileges over time.

6. No expiry for temporary access

Temporary access should have defined expiry or periodic review.

7. No evidence

The organization may revoke access correctly but fail to demonstrate when and how it happened.

8. Ignoring physical access

Digital access and physical access should be addressed separately.


28. Startup-Friendly Implementation

A startup can implement a simple centralized workflow:

HR / Manager / Security Request
↓
Access Inventory
↓
IT Revocation
↓
System Owner Verification
↓
Security Verification for Privileged Access
↓
Evidence Attached to Ticket
↓
Access Record Updated
↓
Closed

A centralized IT/security ticket can be the primary record, with screenshots, logs, or system reports attached as evidence.


29. Minimum Access Revocation Checklist

For a small organization, the minimum process should cover:

  • ☐ Confirm user and effective date/time
  • ☐ Disable identity/SSO account
  • ☐ Remove MFA/authentication methods
  • ☐ Disable email
  • ☐ Revoke VPN/remote access
  • ☐ Remove SaaS access
  • ☐ Remove source-code access
  • ☐ Remove cloud access
  • ☐ Remove privileged access
  • ☐ Revoke tokens/keys
  • ☐ Remove physical access
  • ☐ Terminate sessions where applicable
  • ☐ Verify revocation
  • ☐ Retain evidence
  • ☐ Close the request

30. Relationship With Other ISMS Documents

The Access Revocation Checklist should work together with:

  • Access Control Policy
  • Joiner-Mover-Leaver Procedure
  • Employee Offboarding Checklist
  • Contractor Offboarding Checklist
  • IT Asset Handover Form
  • Asset Return Checklist
  • Asset Inventory
  • Asset Ownership Register
  • SaaS Application Register
  • Cloud Asset Inventory
  • Information Classification Policy
  • Acceptable Use Policy
  • Employee IT Usage Policy
  • Remote Working Policy
  • BYOD Policy
  • Privileged Access Management Procedure
  • Security Incident Management Procedure
  • Risk Assessment and Risk Register

The overall relationship is:

User Lifecycle → Access Request → Approval → Provisioning → Review → Change/Transfer → Revocation → Verification → Evidence


31. ISO 27001 Connection

Access revocation supports the organization’s access-control processes, particularly activities concerning:

  • Access rights
  • Identity management
  • Authentication information
  • Access restriction
  • Privileged access
  • Information access
  • Cloud services
  • User endpoint access
  • Supplier/third-party access

The specific controls applicable to the organization should be determined through its risk assessment and Statement of Applicability (SoA).


32. Final Audit Trail

An auditor should be able to select a departed employee, contractor, transferred employee, or expired temporary account and trace:

Access Request / Exit Event
↓
User & Access Inventory
↓
Approval
↓
Account Revocation
↓
Cloud/SaaS/VPN/Source-Code Revocation
↓
Token/Key Revocation
↓
Verification
↓
Evidence
↓
Closure

Final Principle

Identify → Approve → Revoke → Verify → Record → Evidence → Close

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *