Evidence
Privileged access: the control auditors test hardest
Auditors focus here because the list is short enough to test exhaustively and the consequence of a gap is total.
Facts checked — 2026-09-11
What do auditors test about privileged access?
Who holds administrative access to production, identity systems and the cloud account; whether each of them needs it; whether multi-factor authentication is enforced without exception; whether access is time-bound or standing; and whether privileged actions are logged somewhere the privileged user cannot alter.
The recurring findings are unglamorous: a shared administrative account, a service account with a password in a repository, a former contractor still holding a role, break-glass credentials nobody has rotated since they were created.
The bottom line
Enumerate every account with production or identity administration rights, and justify each one. The list is usually longer than expected.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.