grc-scan

Cyber Essentials question · User access control

Are administrator accounts separate from everyday accounts, and are leavers' accounts removed promptly?

Why assessors ask this

Day-to-day work should use a standard account; admin rights only when needed. Remove access as soon as someone leaves.

What “good” looks like for User access control

  • Turn on MFA for every account that supports it — email and cloud services first.
  • Give each person their own login; remove shared accounts.
  • Use separate admin accounts and a leaver checklist that revokes access on day one.

See where you stand in 5 minutes

Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.

Start the free readiness check

Part of the User access control control.

This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.