Data subject access request: one month, everything you hold, no charge
A DSAR is not a support ticket. The clock starts on receipt, the scope is everything, and the exemptions are narrower than most teams assume.
Access accumulates. A user access review is the periodic check that every permission still has a reason — and the record proving someone looked.
A user access review is a periodic exercise in which the people who own a system or a dataset confirm, name by name, that everyone with access to it still needs that access. It exists because permissions are granted continuously and revoked almost never: people change teams, projects end, contractors finish, and the rights stay.
The review is not an IT task, even though IT runs the report. Only the owner of the system knows whether a particular person still needs to approve payments or read the customer database. IT can tell you who has access; it cannot tell you who should.
The fourth item is where most reviews fail. A review that produced a list of removals nobody carried out is worse than no review: it creates a document asserting that access was corrected when it was not, and that document is the one an auditor or an investigator will read.
Reviewing role names rather than capabilities produces confident wrong answers. An owner asked whether Jane should have "Finance Contributor" will say yes; the same owner asked whether Jane should be able to change bank details on suppliers may say no. Translate before you ask.
Access reviews appear in almost every control framework and security questionnaire, and they are also the control most often performed once and abandoned. The reason is that the first review is a clean-up — large, slow and full of surprises — while later ones are short if joiners, movers and leavers are handled properly in between.
If your reviews are still painful after the second cycle, the problem is upstream: access is being granted without an owner, or leavers are not triggering removal. Fixing that makes the review a confirmation rather than an excavation.
Ettex is not an identity governance platform, and this is where the honest boundary sits: the entitlements live in each system that grants them. What Ettex Records holds is the review itself — the list that was circulated, the decision against each line, the evidence of removal and the sign-off — so the control produces a durable record instead of an email thread. That record is what an auditor asks for, and what your own internal controls testing samples.
Quarterly for systems holding money, personal data or production access; annually for lower-risk systems. Regulated environments and specific frameworks may set the frequency for you.
The business owner of the system or data, not IT and not the users themselves. IT supplies the access list and executes the removals.
They describe the same control; certification emphasises the formal attestation the reviewer makes. Some frameworks use one term, some the other.
Yes, and they are frequently excluded by accident. A service account with broad rights and no owner is exactly the account an attacker looks for.
A DSAR is not a support ticket. The clock starts on receipt, the scope is everything, and the exemptions are narrower than most teams assume.
The SoA lists every Annex A control, whether you apply it, and why. It is the map between your risk assessment and everything else in the certificate.
Sarbanes-Oxley is short. What consumes a finance team is proving that controls operated all year — and proving it with records made at the time.