What to Provide
An offboarding checklist/termination ticket (or similar evidence) for a sample of employees termination during the audit period demonstrating the date that IT access to any in-scope production system components for the sampled terminated employees was revoked.
NOTE: The audit team will communicate sample selections once they have been finalized. Please refrain from attaching evidence to this ER until samples have been communicated.
Evidence Format
Word/PDF document, exported images in a common image file type (i.e. .jpg, .png, .pdf), Excel/.csv export from the source system
Additional Guidance
The evidence should demonstrate:
Name of employee
Date of termination
Date system access was removed
List of access to systems that was removed
If an offboarding checklist/termination ticket is not maintained, a screenshot demonstrating the date that the sampled terminated user's access was revoked from a system log can suffice.
Associated Unified Control ID | Associated Framework Control |
CTRL-535 | LCL-37 |