ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Access Revocation Evidence Register

Access Revocation Evidence Register

1. Purpose

The Access Revocation Evidence Register provides a centralized record of evidence demonstrating that user access has been removed, disabled, modified, or otherwise controlled when access is no longer required.

The register supports:

  • Employee offboarding
  • Contractor offboarding
  • Role changes
  • Privileged access removal
  • Emergency access revocation
  • Access termination following security incidents
  • Periodic access reviews
  • Internal audits
  • ISO 27001 audits
  • SOC 2 examinations
  • Security investigations

Core Principle

Identify → Revoke → Evidence → Verify → Record → Close


2. Scope

This register applies to access revocation involving:

  • Employees
  • Contractors
  • Consultants
  • Interns
  • Temporary workers
  • Supplier personnel
  • Privileged users
  • Service-account owners
  • Other authorized users

It may cover:

  • Corporate identity
  • Email
  • SSO
  • VPN
  • Cloud platforms
  • AWS
  • Azure
  • Google Cloud
  • Production systems
  • Databases
  • Source-code repositories
  • CI/CD
  • SaaS applications
  • Security tools
  • Customer environments
  • Physical access
  • API keys
  • SSH keys
  • Tokens
  • Certificates
  • Other authentication mechanisms

3. Register Ownership

FieldDetails
Register Owner
Security Owner
IAM Owner
Review Frequency
Register Location
Retention Period
Last Review Date
Next Review Date

4. Access Revocation Record

Create one record for each significant access-revocation event.

FieldDetails
Revocation ID
User Name
User ID
User Type☐ Employee ☐ Contractor ☐ Supplier ☐ Other
Department/Company
Role
Privileged User☐ Yes ☐ No
Revocation Trigger
Effective Date
Effective Time
Requested By
Approved By
Revoked By
Verified By
Completion Date
Overall Status

5. Revocation Trigger

Select the reason for access revocation.

☐ Employee termination
☐ Employee resignation
☐ Contractor offboarding
☐ Contract expiry
☐ Role change
☐ Transfer
☐ Access no longer required
☐ Privileged access removal
☐ Project completion
☐ Security incident
☐ Suspected account compromise
☐ Policy violation
☐ Emergency revocation
☐ Periodic access review
☐ Other: ______________________

Trigger Evidence

Reference: ______________________________

Evidence Location: ________________________


6. Access Revocation Evidence Register

Revocation IDUserSystemAccess TypeActionEvidence ReferenceVerified ByStatus

Status

☐ Pending
☐ Revocation in Progress
☐ Revoked
☐ Verification Pending
☐ Exception
☐ Closed


7. Detailed Evidence Record

For important or high-risk access revocations, record the evidence in greater detail.

FieldDetails
Evidence ID
Revocation ID
User
System/Application
Environment☐ Production ☐ Development ☐ Test ☐ Corporate
Access Type
Privilege Level☐ Standard ☐ Elevated ☐ Privileged
Revocation Action
Action Date/Time
Performed By
Evidence Type
Evidence Location
Evidence Date
Verification Method
Verified By
Verification Date
Result☐ Successful ☐ Failed ☐ Exception
Comments

8. Evidence Types

Acceptable evidence may include:

☐ IAM audit log
☐ Access-management system record
☐ User-account status
☐ SSO audit log
☐ Application audit log
☐ Cloud IAM record
☐ AWS CloudTrail evidence
☐ Azure audit log
☐ Google Cloud audit log
☐ VPN access record
☐ GitHub/GitLab/Bitbucket audit log
☐ Database access record
☐ CI/CD access record
☐ SaaS audit log
☐ Security-tool audit log
☐ Physical-access record
☐ Ticket/change record
☐ Access-review record
☐ Screenshot
☐ System-generated report
☐ Email confirmation
☐ Supplier confirmation
☐ Other: ______________________

System-generated evidence should generally be preferred over manually created screenshots where reliable audit logs are available.


9. Corporate Identity Evidence

Record evidence for the organization’s primary identity system.

☐ User disabled
☐ User deleted where appropriate
☐ Group membership removed
☐ Privileged role removed
☐ SSO access removed
☐ Active sessions terminated
☐ MFA methods revoked
☐ Recovery methods removed
☐ Authentication tokens revoked

Evidence

Evidence ID: ______________________

System: ___________________________

Timestamp: ________________________

Evidence Location: _________________


10. AWS Access Revocation Evidence

Where AWS access is involved, record evidence such as:

☐ IAM Identity Center assignment removed
☐ IAM role removed
☐ IAM group membership removed
☐ IAM user disabled/deleted
☐ Access key disabled/deleted
☐ Temporary credentials expired
☐ Cross-account role access removed
☐ Administrator role removed
☐ MFA/authentication method addressed
☐ Active session addressed
☐ CloudTrail activity reviewed where required

AWS Evidence

AWS AccountRole/PermissionActionEvidence IDVerified

Evidence Reference

CloudTrail/Event Reference: __________________________

IAM Evidence: ______________________________________

Verification: _______________________________________


11. Azure Access Evidence

Where Azure is involved:

☐ User disabled
☐ Entra ID roles removed
☐ Subscription roles removed
☐ Resource-group roles removed
☐ Privileged Identity Management access removed
☐ Sessions/tokens addressed
☐ MFA/authentication methods addressed

Evidence

Evidence ID: ______________________

Audit Log Reference: ______________

Verification: _____________________


12. Google Cloud Access Evidence

Where Google Cloud is involved:

☐ User access removed
☐ IAM roles removed
☐ Project permissions removed
☐ Organization permissions removed
☐ Service-account relationships reviewed
☐ Credentials revoked where required

Evidence

Evidence ID: ______________________

Audit Log Reference: ______________

Verification: _____________________


13. Production Access Evidence

For production access:

SystemUserPrivilegeRevocation ActionEvidenceVerified

Evidence may include:

  • IAM logs
  • Kubernetes audit logs
  • SSH access records
  • VPN records
  • Production console audit logs
  • Database access logs
  • PAM records
  • Change-management records

14. Source-Code Access Evidence

Record evidence for:

☐ GitHub
☐ GitLab
☐ Bitbucket
☐ Azure DevOps
☐ Other repository

Verify:

☐ Repository access removed
☐ Organization role removed
☐ SSH key revoked
☐ Personal access token revoked
☐ OAuth authorization revoked
☐ Deployment access removed
☐ Administrative role removed

Evidence

PlatformRepository/OrganizationActionEvidenceVerified

15. Database Access Evidence

Where database access is involved:

☐ User disabled
☐ Database role removed
☐ Administrative privilege removed
☐ Database credentials revoked
☐ Shared credentials rotated where required
☐ Connection access removed

Evidence

Database: ______________________________

User/Role: ______________________________

Action: _________________________________

Evidence Reference: _____________________

Verified By: ____________________________


16. VPN and Network Access Evidence

Verify:

☐ VPN account disabled
☐ Network group membership removed
☐ Firewall access removed
☐ Remote-access certificate revoked
☐ Network authentication removed
☐ Active sessions terminated

Evidence

System: ______________________________

Evidence Reference: ___________________

Date/Time: ____________________________

Verified By: __________________________


17. SaaS Access Evidence

Record evidence for administrative or sensitive SaaS access.

Examples:

  • Microsoft 365
  • Google Workspace
  • Slack
  • Jira
  • Salesforce
  • CRM
  • HR systems
  • Security platforms
  • Monitoring platforms
SaaSUserRoleActionEvidenceVerified

18. API Keys, Tokens and SSH Keys

Determine whether access revocation requires credential invalidation.

☐ API keys revoked
☐ Personal access tokens revoked
☐ OAuth tokens revoked
☐ SSH keys revoked
☐ Cloud access keys revoked
☐ Certificates revoked
☐ Service credentials reviewed
☐ Shared secrets rotated

Evidence

Credential TypeSystemActionEvidenceVerified

Important: Never store the actual secret value in this register.

Record only the credential identifier, system, action, timestamp, and evidence reference.


19. Shared Credential Evidence

If the user knew a shared credential:

☐ Shared credential identified
☐ Risk assessed
☐ Credential rotated
☐ New credential securely distributed
☐ Old credential invalidated
☐ Vault record updated
☐ Access ownership updated

Evidence

System: ______________________________

Credential Identifier: ________________

Rotation Date: ________________________

Evidence Reference: ___________________


20. Physical Access Evidence

Where applicable:

☐ Access card disabled
☐ Building access removed
☐ Data-center access removed
☐ Restricted-area access removed
☐ Keys recovered
☐ Biometric access removed

Evidence

Access System: _______________________

Record ID: ___________________________

Date/Time: ___________________________


21. Verification Evidence

Access revocation should be verified according to the risk of the access.

Verification Methods

☐ Audit-log review
☐ Account-status review
☐ Role-assignment review
☐ Controlled login test
☐ Access-attempt validation
☐ System-owner confirmation
☐ IAM confirmation
☐ Cloud administrator confirmation
☐ Supplier confirmation
☐ Other: ______________________

Verification Record

Revocation IDVerification MethodVerified ByDateResult

22. Independent Verification

For high-risk or privileged access, independent verification should be performed where practical.

☐ Required
☐ Not Required

Independent Reviewer

Name: ______________________________

Role: _______________________________

Date: _______________________________

Result: ☐ Successful ☐ Exception

Reviewer Comments


23. Evidence Integrity

Where evidence is important to an investigation, audit, or legal matter, consider recording:

  • Evidence source
  • Evidence creation date/time
  • Evidence collection date/time
  • Collector
  • Original system
  • Evidence location
  • File name/reference
  • Hash/checksum where appropriate
  • Chain-of-custody reference where required

Evidence Integrity Record

Evidence IDSourceCollected ByCollection DateIntegrity MethodReference

Routine access-revocation evidence does not necessarily require forensic chain-of-custody procedures unless the evidence is being preserved for an investigation or legal matter.


24. Evidence Repository

Record where supporting evidence is stored.

Evidence IDEvidence TypeRepositoryPath/ReferenceAccess Restricted

Evidence repositories should have appropriate access restrictions and retention controls.


25. Evidence Retention

Retain access-revocation evidence according to:

  • Organizational retention requirements
  • Audit requirements
  • Contractual requirements
  • Legal requirements
  • Regulatory requirements
  • Security investigation requirements

Retention

Retention Period: __________________________

Review/Deletion Date: ______________________

Evidence should not be retained indefinitely without a legitimate business, legal, regulatory, or audit requirement.


26. Exceptions

Record any access that could not be revoked as planned.

Revocation IDSystemAccessReasonRiskTemporary ControlOwnerDue Date

Examples:

  • System unavailable
  • Third-party dependency
  • Service account dependency
  • Emergency operational requirement
  • Technical limitation

Exceptions should be tracked until closure.


27. Failed Revocation

If access revocation fails:

☐ Failure identified
☐ Security notified
☐ System owner notified
☐ Risk assessed
☐ Temporary control implemented
☐ Credential/session addressed
☐ Root cause investigated
☐ Successful revocation confirmed
☐ Evidence updated

Failure Details


28. Emergency Revocation Evidence

For emergency access revocation:

Reason: ______________________________

Requested By: ________________________

Effective Time: _______________________

Action Taken: _________________________

System: ______________________________

Evidence Reference: ___________________

Verified By: __________________________

Verification Time: ____________________

Follow-Up Review Required: ☐ Yes ☐ No

Emergency revocation should be documented even when normal approval steps cannot be completed before the access is removed.


29. Evidence Quality Check

Before closing the record, verify:

☐ Evidence identifies the correct user
☐ Evidence identifies the correct system
☐ Evidence demonstrates the required action
☐ Date/time is available
☐ Evidence source is known
☐ Evidence has not been unnecessarily altered
☐ Evidence can be retrieved
☐ Evidence is access-controlled
☐ Evidence retention requirement is known
☐ Independent verification completed where required


30. Final Revocation Record

Revocation ID: ______________________________

User: ______________________________________

Reason: ____________________________________

Effective Date/Time: _________________________

Systems Covered: ____________________________

Privileged Access: ☐ Yes ☐ No

Production Access: ☐ Yes ☐ No

Cloud Access: ☐ Yes ☐ No

Customer Access: ☐ Yes ☐ No

All Required Access Revoked: ☐ Yes ☐ No

Exceptions: ☐ None ☐ Documented

Evidence Complete: ☐ Yes ☐ No

Independent Verification: ☐ Completed ☐ Not Required

Final Status: ☐ Closed ☐ Open


31. Final Approval

Person Performing Revocation

Name: ______________________________

Role: _______________________________

Date: _______________________________

Signature/Approval: __________________

Reviewer

Name: ______________________________

Role: _______________________________

Date: _______________________________

Signature/Approval: __________________

Security/Business Owner

Name: ______________________________

Date: _______________________________

Approval: ____________________________


32. AWS SaaS Startup Example

A SaaS startup terminates a DevOps contractor who has:

  • AWS access
  • Production Kubernetes access
  • GitHub access
  • CI/CD access
  • Production database access
  • VPN access

Evidence Register

SystemActionEvidence
AWS IAM Identity CenterAssignment removedIAM audit record
AWS IAMPrivileged roles removedIAM audit record
GitHubOrganization access removedGitHub audit log
SSHKey revokedAccess-management record
KubernetesAdmin role removedKubernetes audit log
DatabaseUser/role disabledDatabase audit record
CI/CDDeployment access removedCI/CD audit log
VPNAccount disabledVPN audit log

Verification

The security reviewer checks:

  1. Contractor account is disabled.
  2. AWS privileged roles are no longer assigned.
  3. GitHub organization access is removed.
  4. Production Kubernetes permissions are removed.
  5. Database access is removed.
  6. VPN access is disabled.
  7. Shared production credentials known to the contractor have been rotated.

The reviewer records the evidence references and closes the revocation record.

Audit Trail

Offboarding Request → Access Inventory → Revocation → Evidence Collection → Independent Verification → Exception Review → Closure


33. Startup-Friendly Model

A startup does not need a complicated evidence system.

For each significant access revocation, retain at least:

1. Who — User and role

2. Why — Termination, role change, contract end, etc.

3. What — Systems and access removed

4. When — Revocation date/time

5. How — Method used to revoke access

6. Evidence — System-generated record or audit log

7. Who verified — Reviewer

8. Exceptions — Anything not completed

This creates a simple but defensible audit trail.


34. Common Mistakes

Avoid:

  • Recording only that “access was removed.”
  • Failing to identify the system.
  • Failing to record the revocation date/time.
  • Storing actual passwords or API keys as evidence.
  • Relying only on screenshots when reliable audit logs exist.
  • Forgetting cloud access.
  • Forgetting privileged roles.
  • Forgetting API keys and tokens.
  • Forgetting active sessions.
  • Failing to verify revocation.
  • Allowing exceptions without owners.
  • Keeping sensitive evidence in unrestricted folders.
  • Deleting evidence immediately after the access change.
  • Retaining evidence indefinitely without a defined requirement.

35. Relationship With Other ISMS Documents

DocumentRelationship
Access Revocation ChecklistDefines access-removal activities
Access Management ProcedureDefines access lifecycle
Privileged User Offboarding ChecklistCovers privileged access removal
Employee Offboarding PolicyCovers employee exit
Contractor Offboarding ProcedureCovers contractor exit
Exit Security AcknowledgementRecords individual security acknowledgement
Access Review ProcedureReviews ongoing access
IAM ProcedureDefines identity and access management
Incident Response ProcedureSupports emergency access revocation
Evidence Preservation ProcedureHandles investigation evidence
Asset Return ChecklistHandles company assets
Access RegisterRecords authorized access

36. ISO 27001 / SOC 2 Connection

The Access Revocation Evidence Register provides supporting evidence that access is removed or adjusted when it is no longer required and that access-control activities are documented and reviewable.

It can support evidence for areas including:

  • Identity management
  • Access control
  • Privileged access
  • Authentication
  • Personnel offboarding
  • Supplier offboarding
  • Information protection
  • Security monitoring
  • Incident response

For ISO 27001, the specific applicable controls and evidence should be determined through the organization’s risk assessment and Statement of Applicability.

For SOC 2, the register can provide a structured audit trail demonstrating that access termination activities occurred and were independently reviewed where required.


37. Quick Audit Checklist

☐ User identified
☐ Revocation trigger documented
☐ Effective date/time documented
☐ Access inventory completed
☐ Corporate access revoked
☐ Cloud access revoked
☐ AWS access revoked
☐ Production access revoked
☐ Database access revoked
☐ Source-code access revoked
☐ CI/CD access revoked
☐ VPN access revoked
☐ SaaS access revoked
☐ Privileged access revoked
☐ API tokens addressed
☐ SSH keys addressed
☐ Shared credentials assessed
☐ Sessions addressed
☐ Physical access addressed
☐ Evidence reference recorded
☐ Evidence source identified
☐ Verification completed
☐ Exceptions documented
☐ Evidence retained appropriately
☐ Final approval completed
☐ Register closed


38. Final Audit Trail

For every significant access-revocation event, the organization should be able to demonstrate:

Who was the user?
Why was access revoked?
When was access required to be revoked?
What systems and privileges were affected?
What action was performed?
Who performed the action?
What evidence proves the action occurred?
Who verified the revocation?
Were privileged, cloud, production, and external accesses addressed?
Were credentials, tokens, keys, and shared secrets considered?
Were exceptions documented?
Where is the supporting evidence stored?
Who approved closure?

Final Principle

Access revocation is not complete when someone says access was removed. It is complete when the organization can demonstrate what was revoked, when it was revoked, who performed it, who verified it, and where the evidence is retained.