Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
BETA
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon
Browse
Ctrl+K
98 controls
03.01.01
Account management
Access control
3 evidence1 control
03.01.02
Access enforcement
Access control
2 evidence1 control
03.01.03
Information flow enforcement
Access control
2 evidence1 control
03.01.04
Separation of duties
Access control
3 evidence1 control
03.01.05
Least privilege
Access control
2 evidence1 control
03.01.06
Least privilege - privileged accounts
Access control
3 evidence1 control
03.01.07
Least privilege - privileged functions
Access control
2 evidence1 control
03.01.08
Unsuccessful logon attempts
Access control
2 evidence1 control
03.01.09
System use notification
Access control
2 evidence1 control
03.01.10
Device lock
Access control
2 evidence1 control
03.01.11
Session termination
Access control
2 evidence1 control
03.01.12
Remote access
Access control
3 evidence1 control
03.01.16
Wireless access
Access control
2 evidence1 control
03.01.18
Access control for mobile devices
Access control
3 evidence1 control
03.01.20
Use of external systems
Access control
2 evidence1 control
03.01.22
Publicly accessible content
Access control
3 evidence1 control
03.02.01
Literacy training and awareness
Awareness and training
3 evidence1 control
03.02.02
Role-based training
Awareness and training
2 evidence1 control
03.03.01
Event logging
Audit and accountability
3 evidence1 control
03.03.02
Audit record content
Audit and accountability
2 evidence1 control
03.03.03
Audit record generation
Audit and accountability
2 evidence1 control
03.03.04
Response to audit logging process failures
Audit and accountability
2 evidence1 control
03.03.05
Audit record review, analysis, and reporting
Audit and accountability
3 evidence1 control
03.03.06
Audit record reduction and report generation
Audit and accountability
2 evidence1 control
03.03.07
Time stamps
Audit and accountability
2 evidence1 control
03.03.08
Protection of audit information
Audit and accountability
3 evidence1 control
03.04.01
Baseline configuration
Configuration management
2 evidence1 control
03.04.02
Configuration settings
Configuration management
2 evidence1 control
03.04.03
Configuration change control
Configuration management
3 evidence1 control
03.04.04
Impact analyses
Configuration management
2 evidence1 control
03.04.05
Access restrictions for change
Configuration management
2 evidence1 control
03.04.06
Least functionality
Configuration management
2 evidence1 control
03.04.08
Authorized software - allow by exception
Configuration management
2 evidence1 control
03.04.10
System component inventory
Configuration management
2 evidence1 control
03.04.11
Information location
Configuration management
2 evidence1 control
03.04.12
System and component configuration for high-risk areas
Configuration management
2 evidence1 control
03.05.01
User identification, authentication, and re-authentication
Identification and authentication
2 evidence1 control
03.05.02
Device identification and authentication
Identification and authentication
2 evidence1 control
03.05.03
Multi-factor authentication
Identification and authentication
3 evidence1 control
03.05.04
Replay-resistant authentication
Identification and authentication
2 evidence1 control
03.05.05
Identifier management
Identification and authentication
2 evidence1 control
03.05.07
Password management
Identification and authentication
3 evidence1 control
03.05.11
Authentication feedback
Identification and authentication
2 evidence1 control
03.05.12
Authenticator management
Identification and authentication
3 evidence1 control
03.06.01
Incident handling
Incident response
3 evidence1 control
03.06.02
Incident monitoring, reporting, and response assistance
Incident response
3 evidence1 control
03.06.03
Incident response testing
Incident response
2 evidence1 control
03.06.04
Incident response training
Incident response
2 evidence1 control
03.06.05
Incident response plan
Incident response
3 evidence1 control
03.07.04
Maintenance tools
Maintenance
3 evidence1 control
03.07.05
Non-local maintenance
Maintenance
3 evidence1 control
03.07.06
Maintenance personnel
Maintenance
4 evidence1 control
03.08.01
Media storage
Media protection
3 evidence1 control
03.08.02
Media access
Media protection
3 evidence1 control
03.08.03
Media sanitization
Media protection
3 evidence1 control
03.08.04
Media marking
Media protection
3 evidence1 control
03.08.05
Media transport
Media protection
3 evidence1 control
03.08.07
Media use
Media protection
3 evidence1 control
03.08.09
System backup - cryptographic protection
Media protection
3 evidence1 control
03.09.01
Personnel screening
Personnel security
3 evidence1 control
03.09.02Personnel termination and transferITSP.10.171Personnel security
Official Requirement
A. When individual employment is terminated: 1. disable system access within [Assignment: organization-defined time period] 2. terminate or revoke authenticators and credentials associated with the individual 3. retrieve security-related system property B. When individuals are reassigned or transferred to other positions in the organization: 1. review and confirm the ongoing operational need for current logical and physical access authorizations to the system and facility 2. modify access authorization to correspond with any changes in operational need
Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3
In Plain English
When someone leaves the organization, their access must be disabled promptly, all credentials revoked, and all company-issued security property (badges, laptops, tokens) collected. When someone transfers to a new role, their access must be reviewed and adjusted to match their new responsibilities -- old access they no longer need must be removed.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Termination and transfer access management
Implementation Steps
Integrate HR termination events with your identity provider to automatically disable accounts within the defined time period (e.g., same day)
Automate revocation of all authenticators (passwords, MFA tokens, API keys, SSH keys, certificates) upon termination
Implement an offboarding checklist that includes retrieval of all security-related property (laptops, badges, tokens, keys)
For transfers, trigger an access review workflow that requires the new manager to confirm needed access and revoke access no longer required
Tools / Systems
Identity provider with HR integration (Okta, Azure AD, Google Workspace)SCIM provisioning for automated deprovisioningOffboarding checklist (ServiceNow, Jira, BambooHR)Access review workflow for transfers (GRC platform or identity governance tool)
Typical Control Termination and transfer access management