04 · Selected Work

Identity & Access Management Review

IAM Access Control ISO A.5

Performed an identity and access management review to assess user provisioning, privileged access, account lifecycle management, and segregation of duties within a simulated enterprise environment.

Role
IT Auditor
Environment
Windows Active Directory Lab
Framework Mapping
ISO 27001 Annex A.5
Overview

Access management is one of the most critical security controls. This project focused on reviewing how users receive, modify, and lose access while ensuring permissions align with business responsibilities.

Objectives
Tools & Stack
Process

Collected account inventories, analyzed group memberships, reviewed privileged accounts, verified inactive users, and compared permissions against organizational roles.

Findings & Deliverables
Outcome & Reflection

This project enhanced my understanding of access governance and reinforced how identity management supports compliance, operational security, and risk reduction.

Selected Work