Document users, roles and clients
Document the access structure of a data processing system: roles with permissions, users, clients and external operating parties. These four sublists are the evidence an ISMS audit expects to see for access control.
For every data processing system, four sublists record who accesses it with which permissions via which end devices, and which external parties are responsible for operation. This is the evidence that internal and external auditors sample when they review access control under ISO 27001 or BSI IT-Grundschutz.
Prerequisites
- You have access to the parent data processing system.
- You have permission to edit the data processing system.
- Create the “Roles” first: when you create users, you select their roles from the roles already defined in the system.
Create roles with permissions
The “Roles” section holds the permission concept, with the columns “Designation”, “Permissions” and “Additional permissions”.
- In the “Roles” section, click “New”.
- Enter the “Designation” (mandatory field, for example
Administrator,Purchasing,Warehouse) and add a “Description”. - Under “Permissions”, tick “Read right”, “Right to edit”, “Right to create” and “Right to delete”. Grant only what the role genuinely needs — this is your evidence for the least privilege principle.
- Record role-specific special permissions under “Additional permissions” and the applicable “Password policy” (minimum length, complexity, change interval).
- In the field “Process for granting / denying users access to this data processing system”, describe how access is assigned and how it is revoked again.
- Click “Create”.
Record users
- In the “Users” section, click the arrow icon next to “New” and select “Create user”, or “Load from contacts” to adopt several existing contacts at once.
- Fill in “Name of the company”, “First name”, “Surname”, “Position” and “Username” — the username is the login name stored in the system and therefore the anchor of every permission review.
- Select the applicable entries under “Roles” and record the “Obligations”, for example the IT usage policy.
- Click “Create”.
Document clients and external parties
- In the “Clients” section, click “New”. Enter the “Designation” and select the “Type” (for example “Mobile”, “Desktop”, “Thin client”), the “Administration” (“Managed (centrally managed)”, “Unmanaged” or “BYOD”) and the “Operating system”.
- Set “Endpoint protection / MDM in place?” to “Yes” or “No” and add the “Documentation reference”, for example the inventory number.
- In the “Administration and management” section, click the arrow icon next to “New”, select “Create administrator” and set the “Type of contact” to “Hosting provider”, “Support”, “Supplier”, “System coordinator” or “Other”.
- Click “Create” in each case. To change an entry, click a line in the table and choose “Edit” at the top right, or “Delete” in the “Actions” selection menu.
Practical tips
- The field “Process for granting / denying users access to this data processing system” is regularly the first sample point in an audit, and the most common finding is that no documented process exists. Even one sentence such as
Assignment and removal by IT service desk based on written approval from the supervisor, documented in the ticketing systemcloses that gap. - Record every hosting provider and every external service provider with data access, and link it to the “Contacts” module via “Load from contacts”. In a security incident, whom you have to reach technically is then visible directly on the affected system.
- Every change to the four sublists is logged in the activity history of the data processing system, so you can demonstrate continuous maintenance of the access structure.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.