Skip to content
HEM Bilişim
Knowledge base

Access rights review

Periodically verifying who can reach what. This is where most audit findings originate.

When to use it: Periodically (quarterly or half-yearly) and before an audit.

Steps

  1. 01

    Produce the permission inventory

    Which account with which role in which system. List it application by application; a forgotten system always turns up.

  2. 02

    Find the orphaned accounts

    Leavers, finished projects, service accounts no longer in use. Any account with no clear owner is a candidate for closure.

  3. 03

    Send the list to the managers

    Each manager gets their own team's permission list. The decision is theirs; your job is to present the list accurately and readably.

  4. 04

    Remove what is not approved

    The point of a review is the removal. If unapproved permissions are not removed, the process only produces paper.

  5. 05

    Handle privileged accounts separately

    Administrator accounts, shared passwords and standing elevated permissions go on a separate list and are reviewed more often.

  6. 06

    Keep the record

    Who approved what and when. This record is what you show the auditor, not the list itself.

Common mistakes

  • Running the review through an email chain.
  • Not following up on removing unapproved permissions.
  • Leaving service accounts out of scope.

The guides describe general practice and are not legal advice. Refer to the official source for the current text of the legislation.

See where you stand in 20 minutes

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation