ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Access Revocation Checklist

Access Revocation Checklist

1. Purpose

The Access Revocation Checklist provides a structured process for removing user, system, application, cloud, privileged, physical, and remote access when access is no longer required.

The objective is to ensure that access is:

  • Revoked promptly
  • Revoked from all relevant systems
  • Based on an authorized trigger
  • Verified after removal
  • Supported by appropriate evidence
  • Coordinated with credential and session management
  • Addressed across cloud, SaaS, production, source-code, database, and physical environments
  • Completed without leaving orphaned accounts, tokens, keys, or permissions

Core Principle

Identify → Authorize → Inventory → Revoke → Disable → Rotate → Verify → Record → Close


2. When to Use

Use this checklist when access must be removed because of:

☐ Employee termination
☐ Employee resignation
☐ Employee role change
☐ Department transfer
☐ Contractor termination
☐ Consultant termination
☐ Temporary access expiry
☐ Project completion
☐ Privileged access removal
☐ Security incident
☐ Suspected account compromise
☐ Access no longer required
☐ Supplier termination
☐ Application retirement
☐ Credential compromise
☐ Policy violation
☐ Long-term leave
☐ Contract expiry
☐ Other: __________________________


3. Access Revocation Information

FieldDetails
Revocation ID
User/Account Name
Employee/Contractor ID
Department
Current Role
Manager/System Owner
Revocation Trigger
Effective Date
Effective Time
Risk Level
Requested By
Approved By
IT Owner
Security Reviewer
Completion Date

4. Revocation Trigger

Identify why access must be revoked.

☐ Termination
☐ Role change
☐ Temporary access expiry
☐ Project completion
☐ Access review finding
☐ Security incident
☐ Account compromise
☐ Policy violation
☐ Contract termination
☐ Supplier offboarding
☐ Business requirement changed
☐ System/application retirement
☐ Credential compromise
☐ Other: __________________________

Trigger Details


5. Authorization

Confirm that the revocation is authorized.

☐ Request received
☐ Request validated
☐ Identity verified
☐ Manager approval obtained where required
☐ System-owner approval obtained where required
☐ Security approval obtained where required
☐ Emergency revocation authorized where applicable

Requested By: ______________________

Approved By: _______________________

Date: ______________________________


6. Revocation Timing

Determine when access must be removed.

Required Revocation Date: __________________

Required Revocation Time: __________________

Time Zone: __________________

☐ Immediate revocation
☐ Same-day revocation
☐ Scheduled revocation
☐ Expiry-based revocation
☐ Other: __________________________

For high-risk situations, access should be removed as soon as reasonably required by the organization’s incident or access-management process.


7. Access Inventory

Identify all access associated with the user.

☐ Corporate identity
☐ Email
☐ SSO
☐ MFA
☐ VPN
☐ AWS/cloud
☐ GitHub/GitLab/Bitbucket
☐ CI/CD
☐ Production systems
☐ Databases
☐ SaaS applications
☐ Security tools
☐ Monitoring systems
☐ Ticketing systems
☐ CRM
☐ Finance systems
☐ HR systems
☐ Password manager
☐ API access
☐ Service accounts
☐ Physical access
☐ Other systems

Access Inventory

SystemAccountAccess TypePrivilegedRevocation Required
☐☐
☐☐
☐☐

8. Corporate Identity

☐ User account disabled
☐ Account sign-in blocked
☐ SSO access removed
☐ Directory group memberships removed
☐ MFA registration addressed
☐ Authentication methods removed
☐ Recovery email/phone addressed
☐ Active sessions terminated where appropriate
☐ Refresh tokens invalidated where applicable
☐ Account status verified


9. Email Access

☐ Email account disabled
☐ Active sessions terminated
☐ Email tokens invalidated
☐ Mail forwarding reviewed
☐ Automatic forwarding removed
☐ Shared mailbox access removed
☐ Distribution groups reviewed
☐ Calendar access removed
☐ Delegated access removed
☐ Mailbox ownership transferred where required


10. VPN and Remote Access

☐ VPN account disabled
☐ VPN certificates revoked
☐ VPN groups removed
☐ Remote-access permissions removed
☐ Remote-access tokens revoked
☐ Remote sessions terminated
☐ Bastion/jump-host access removed
☐ Remote administration access removed


11. AWS / Cloud Access

If the user has cloud access:

☐ AWS IAM user disabled/deleted where appropriate
☐ IAM role assignments removed
☐ IAM group membership removed
☐ Access keys revoked
☐ Temporary credentials addressed
☐ MFA device addressed
☐ AWS SSO/Identity Center access removed
☐ Cloud administrator access removed
☐ Cloud console access removed
☐ CLI/API access removed
☐ Production cloud access removed
☐ Cloud ownership transferred where required

AWS Revocation Evidence


12. Other Cloud Platforms

Where applicable:

☐ Microsoft Azure access removed
☐ Google Cloud access removed
☐ Cloud organization membership removed
☐ Cloud IAM permissions removed
☐ Service-specific permissions removed
☐ Administrative roles removed
☐ API credentials revoked


13. Source-Code Access

☐ GitHub access removed
☐ GitLab access removed
☐ Bitbucket access removed
☐ Organization membership removed
☐ Repository permissions removed
☐ Branch permissions removed
☐ Code-owner permissions removed
☐ CI/CD access removed
☐ Deployment permissions removed
☐ Personal access tokens revoked
☐ SSH keys removed/revoked
☐ Code-signing access addressed


14. Production Access

If production access exists:

☐ Production account disabled
☐ Production role removed
☐ SSH access removed
☐ Bastion access removed
☐ Kubernetes access removed
☐ Production database access removed
☐ Production cloud permissions removed
☐ Monitoring access removed
☐ Administrative access removed
☐ Emergency access reviewed
☐ Active production sessions terminated where appropriate

Production Revocation

SystemAccessRevokedVerified By
☐
☐
☐

15. Privileged Access

If the user has administrative privileges:

☐ Administrator role removed
☐ Privileged groups removed
☐ Root-equivalent access removed
☐ Privileged cloud access removed
☐ Database administrator access removed
☐ Security administrator access removed
☐ Firewall/network administrator access removed
☐ Privileged sessions terminated
☐ Break-glass access reviewed
☐ Shared administrator credentials rotated where necessary


16. SaaS Applications

Review all SaaS platforms.

ApplicationAccountAccessRevokedVerified
☐☐
☐☐
☐☐
☐☐

Consider:

  • CRM
  • ERP
  • HR
  • Finance
  • Project management
  • Customer support
  • Security platforms
  • Collaboration tools
  • Password managers
  • Analytics platforms
  • Marketing platforms
  • Ticketing platforms

17. Database Access

☐ Database account disabled
☐ Database roles removed
☐ Production database access removed
☐ Development database access removed where no longer required
☐ Read/write permissions removed
☐ Administrative permissions removed
☐ Database tokens/credentials revoked
☐ Connection strings reviewed where necessary


18. API Keys and Tokens

Identify non-password authentication mechanisms.

☐ API keys identified
☐ Personal access tokens identified
☐ OAuth tokens identified
☐ Access tokens revoked
☐ Refresh tokens revoked
☐ SSH keys revoked
☐ Certificates addressed
☐ Cloud access keys revoked
☐ Service credentials reviewed
☐ Shared credentials rotated where required

Credential Rotation Required?

☐ Yes
☐ No

Details


19. Secrets and Passwords

Assess whether the user knew or had access to shared secrets.

☐ Password-manager access removed
☐ Shared passwords reviewed
☐ Administrative passwords reviewed
☐ Service credentials reviewed
☐ Database credentials reviewed
☐ Cloud credentials reviewed
☐ API secrets reviewed
☐ Encryption-key access reviewed
☐ Secrets rotated where required

Do not store actual passwords, API keys, private keys, or secrets in this checklist.


20. MFA and Authentication Devices

☐ MFA device removed
☐ Authenticator registration removed
☐ Hardware security key recovered or invalidated
☐ Smart card revoked
☐ Recovery codes addressed
☐ Backup authentication methods removed
☐ Trusted devices removed
☐ Registered mobile number reviewed


21. Physical Access

☐ Office access card disabled
☐ Restricted-area access removed
☐ Data-center access removed
☐ Secure-area access removed
☐ Physical keys recovered
☐ Visitor privileges removed
☐ Parking/access privileges removed
☐ Other physical permissions removed


22. Customer and Supplier Systems

If external access exists:

☐ Customer portal access removed
☐ Supplier portal access removed
☐ Third-party collaboration access removed
☐ External administrative access removed
☐ Customer-specific accounts disabled
☐ Supplier-specific accounts disabled
☐ External contact ownership transferred


23. Mobile and Endpoint Access

☐ Corporate laptop access removed
☐ Endpoint management account removed
☐ Device certificates revoked
☐ Corporate applications removed where required
☐ Mobile access removed
☐ MDM access reviewed
☐ Remote-wipe capability considered where applicable
☐ Device ownership transferred or recovered


24. Active Sessions

Account disabling alone may not terminate all active sessions.

Where supported:

☐ Web sessions terminated
☐ VPN sessions terminated
☐ Cloud sessions terminated
☐ SaaS sessions terminated
☐ SSH sessions terminated
☐ Remote desktop sessions terminated
☐ API sessions/tokens invalidated
☐ Refresh tokens invalidated

Session Verification


25. Access Groups and Permissions

Review indirect access.

☐ Security groups reviewed
☐ Distribution groups reviewed
☐ Application groups reviewed
☐ Cloud groups reviewed
☐ Database roles reviewed
☐ Repository teams reviewed
☐ Shared-drive permissions reviewed
☐ File-sharing permissions reviewed
☐ Administrative groups reviewed


26. Delegated and Shared Access

Review access granted indirectly through:

☐ Delegation
☐ Shared mailbox
☐ Shared drive
☐ Shared account
☐ Service account
☐ Team account
☐ Application role
☐ Group membership
☐ API integration

Shared Access Action


27. Service Accounts

Determine whether the employee created or controlled service accounts.

☐ Service accounts identified
☐ Ownership reviewed
☐ Passwords/credentials reviewed
☐ API keys reviewed
☐ Access ownership transferred
☐ Credentials rotated where required
☐ Unnecessary service accounts disabled


28. Access Related to Security Tools

Review access to:

☐ SIEM
☐ EDR
☐ Vulnerability scanner
☐ Firewall
☐ WAF
☐ IAM platform
☐ Cloud security platform
☐ Monitoring platform
☐ Incident-management platform
☐ Security ticketing system
☐ Backup platform

Privileged security-tool access should receive particular attention.


29. Information Ownership

Access revocation should not accidentally disrupt business operations.

Before removing access:

☐ Business files transferred
☐ Project ownership transferred
☐ Repository ownership transferred
☐ Customer ownership transferred
☐ Supplier ownership transferred
☐ System ownership transferred
☐ Critical documentation transferred
☐ Shared resources reassigned


30. Security Incident Considerations

If revocation is related to a suspected compromise or security incident:

☐ Incident declared where appropriate
☐ Incident owner notified
☐ Evidence preservation considered
☐ Logs preserved
☐ Active sessions terminated
☐ Credentials revoked
☐ Tokens revoked
☐ Secrets rotated
☐ Relevant systems monitored
☐ Investigation requirements considered

Do not destroy evidence required for investigation merely because access is being revoked.


31. Emergency Access Revocation

For urgent situations:

☐ Emergency authorization obtained
☐ Identity disabled immediately
☐ Privileged access removed
☐ Cloud access removed
☐ Production access removed
☐ VPN removed
☐ Active sessions terminated
☐ Tokens revoked
☐ Secrets rotated where required
☐ Security team notified
☐ Incident record created where appropriate
☐ Detailed review completed after containment


32. Final Verification

A second person should verify critical revocations where practical.

☐ Corporate identity disabled
☐ Email disabled
☐ VPN removed
☐ MFA addressed
☐ AWS/cloud access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ Production access removed
☐ Database access removed
☐ SaaS access removed
☐ Privileged access removed
☐ Physical access removed
☐ Tokens/keys addressed
☐ Shared credentials addressed

Verified By: __________________________

Verification Date: ____________________

Result: ☐ Complete ☐ Exceptions


33. Revocation Testing

Where appropriate, test that revoked access can no longer be used.

☐ Login attempt tested
☐ VPN access tested
☐ Cloud access tested
☐ SaaS access tested
☐ Repository access tested
☐ Production access tested
☐ Physical access tested where appropriate

Testing should be performed carefully to avoid unnecessary security events or account lockouts.


34. Exceptions

Document incomplete or delayed revocations.

ExceptionReasonRiskCompensating ControlOwnerDue DateStatus

Exceptions should be formally approved according to the organization’s risk-management process.


35. Revocation Evidence

Retain appropriate evidence such as:

☐ Access-removal logs
☐ IAM evidence
☐ SaaS deactivation evidence
☐ VPN revocation evidence
☐ Repository access-removal evidence
☐ Privileged-access removal evidence
☐ Physical-access removal evidence
☐ Credential-rotation evidence
☐ Verification record
☐ Approved exception
☐ Incident record where applicable

Do not retain actual credentials or secrets as evidence.


36. Revocation Register

Revocation IDUserTriggerDate/TimeRiskSystemsVerifiedStatus
☐
☐

37. Completion Criteria

Access revocation should not be marked Complete until:

☐ Revocation was authorized
☐ All relevant systems were identified
☐ Corporate identity was addressed
☐ Cloud access was removed
☐ SaaS access was removed
☐ VPN/remote access was removed
☐ Source-code access was removed
☐ Production access was removed
☐ Database access was removed
☐ Privileged access was removed
☐ Tokens and keys were addressed
☐ Shared credentials were reviewed
☐ Physical access was removed
☐ Delegated/group access was reviewed
☐ Business ownership was transferred
☐ Active sessions were addressed
☐ Required testing/verification was completed
☐ Exceptions were documented
☐ Evidence was retained


38. Final Approval

User/Account: ______________________________

Revocation Trigger: ______________________________

Requested By: ______________________________

Approved By: ______________________________

IT Owner: ______________________________

Security Reviewer: ______________________________

Revocation Date/Time: ______________________________

Verification Date/Time: ______________________________

Status

☐ Complete
☐ Complete with Approved Exceptions
☐ Further Action Required

Comments


39. AWS SaaS Startup Example

A developer leaves a SaaS startup.

The employee has:

  • AWS access
  • GitHub access
  • CI/CD access
  • Production database access
  • VPN
  • Slack
  • Corporate email
  • Password-manager access

Revocation Sequence

1. HR/Manager → confirms termination.

2. IT → disables the corporate identity and VPN.

3. Cloud Owner → removes AWS IAM roles, permissions, access keys, and relevant authentication methods.

4. Engineering → removes GitHub and CI/CD permissions.

5. Database Owner → removes production database access.

6. Security → reviews privileged access, tokens, shared credentials, and secrets.

7. SaaS Owners → remove access from business applications.

8. Facilities → disables physical access.

9. Reviewer → independently verifies critical access removal.

Audit Trail

Authorization → Access Inventory → Identity Revocation → Cloud Revocation → Application Revocation → Credential Review → Session Termination → Verification → Evidence → Closure


40. Startup-Friendly Revocation Model

For a small startup, the process can be simplified to seven steps:

1. Identify

Determine why access must be revoked.

2. List

Check:

  • Google/Microsoft account
  • AWS
  • GitHub
  • VPN
  • SaaS
  • Production
  • Database
  • Password manager

3. Revoke

Remove access from all relevant systems.

4. Rotate

Change shared credentials, API keys, or secrets where necessary.

5. Transfer

Transfer ownership of projects, repositories, systems, and business information.

6. Verify

A second person verifies critical access removal.

7. Record

Retain evidence and close the revocation record.


41. Common Mistakes

Avoid:

  • Disabling only the email account.
  • Assuming SSO removal automatically removes every application.
  • Forgetting AWS/cloud access.
  • Forgetting GitHub/GitLab.
  • Forgetting CI/CD.
  • Forgetting production databases.
  • Forgetting VPN access.
  • Forgetting SaaS applications.
  • Forgetting physical access.
  • Forgetting group memberships.
  • Forgetting API keys and tokens.
  • Forgetting active sessions.
  • Forgetting shared credentials.
  • Forgetting service accounts.
  • Removing access without transferring business ownership.
  • Deleting accounts before preserving investigation evidence.
  • Marking access as revoked without verification.
  • Keeping temporary access indefinitely.
  • Failing to document exceptions.

42. Relationship With Other ISMS Documents

DocumentRelationship
Access Management ProcedureDefines the overall access lifecycle
Employee Offboarding PolicyDefines termination/offboarding requirements
Employee Role Change ChecklistHandles access changes during role changes
Joiner-Mover-Leaver ProcedureManages personnel lifecycle
Privileged User Management ProcedureControls privileged access
Cloud Access Review ChecklistReviews cloud permissions
Source Code Access Review ChecklistReviews development access
Access Review ProcedurePerforms periodic access reviews
Identity and Authentication PolicyDefines authentication requirements
Password/Authentication StandardDefines authentication controls
Supplier Offboarding ChecklistHandles third-party access removal
Security Incident Response ProcedureHandles emergency access revocation
Information Security Exception RegisterRecords approved deviations
Corrective Action TrackerTracks unresolved issues
Asset Return ProcedureHandles associated physical assets

43. ISO 27001 Connection

Access revocation supports the organization’s management of access rights, authentication information, privileged access, information protection, personnel changes, and secure termination of access.

The Access Revocation Checklist is not itself a universally mandatory ISO 27001 form. The organization should establish appropriate access-removal processes based on:

  • ISMS scope
  • Risk assessment
  • Information classification
  • System architecture
  • User roles
  • Privileged access
  • Cloud/SaaS environment
  • Legal and regulatory requirements
  • Customer requirements
  • Contractual requirements
  • Business needs

The organization should be able to demonstrate that access is removed when it is no longer required and that critical revocations are appropriately verified.


44. Final Audit Checklist

☐ Revocation request received
☐ Request authorized
☐ User identity verified
☐ Revocation trigger documented
☐ Revocation timing defined
☐ Access inventory completed
☐ Corporate identity disabled
☐ SSO access removed
☐ MFA addressed
☐ Email access removed
☐ VPN access removed
☐ AWS/cloud access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ Production access removed
☐ Database access removed
☐ SaaS access removed
☐ Privileged access removed
☐ Group memberships removed
☐ Delegated access removed
☐ API keys addressed
☐ Tokens revoked
☐ SSH keys addressed
☐ Service accounts reviewed
☐ Shared credentials reviewed
☐ Active sessions terminated
☐ Physical access removed
☐ Customer/supplier access removed
☐ Business ownership transferred
☐ Security incident requirements considered
☐ Emergency revocation completed where applicable
☐ Final verification completed
☐ Exceptions documented
☐ Evidence retained
☐ Revocation record closed


45. Final Audit Trail

For every significant access revocation, the organization should be able to demonstrate:

Why was access revoked?
Who authorized the revocation?
When was access required to be removed?
What systems did the user have access to?
Was corporate identity disabled?
Was cloud/AWS access removed?
Was production access removed?
Was source-code access removed?
Were database and SaaS permissions removed?
Was privileged access removed?
Were groups and delegated permissions reviewed?
Were API keys, tokens, SSH keys, and credentials addressed?
Were active sessions terminated?
Was physical access removed?
Were shared credentials rotated where necessary?
Was business ownership transferred?
Was the revocation independently verified?
Were exceptions documented and approved?
What evidence proves the access was actually revoked?

Final Principle

Access revocation is not complete when an account is disabled. It is complete when all relevant direct and indirect access, privileged permissions, sessions, credentials, tokens, physical access, and security dependencies have been addressed, verified, and recorded.