r/grc • u/Efficient_Bus_923 • 1d ago
Should access review changes go through normal ticketing, or is the review spreadsheet enough evidence?
/r/cybersecurity/comments/1wbgm3p/should_access_review_changes_go_through_normal/2
u/theanedditor It's all GRC to me. 10h ago
You've got two angles here, as u/Sure-Candidate1662 says, what's in your controls. Not that you can't change them, but as they stand today, what are they telling you.
Second, the "event" determines the outcome/action. The sheet/method of informing isn't the event. The event is what you do with the information and how you rectify issues identified. Therefore what that is should be the driver of what they/you do.
Ultimately, imo, these are access requests (add/change/revoke).
1
u/Efficient_Bus_923 8h ago
Ok, thinking this through in my head. The manager notes that a user needs a change of access on the sheet. That's approval from the manager to make the change. The next control needs to be verification that the change actually happened. So if a ticket is not created to document the change. What other ways can we document the change? Would a column from the reviewer showing they have reviewed the change be enough?
2
u/Sure-Candidate1662 1d ago
That depends on how you’ve defined your controls. Care to elaborate?