Review
Privileged Access Review — Siteridgepoint
A full-cycle review of elevated rights on sensitive systems, with facilitated owner attestation and an evidence pack ready for internal or external audit.
Who it is for
Security, risk, and infrastructure leaders who need a defensible view of who can administer critical applications, databases, network devices, and identity stores—especially ahead of audits or regulatory reviews in South Africa.
Result
You receive a reconciled inventory of privileged accounts, owner-confirmed decisions for each high-risk entitlement, residual-risk notes, and an attestation pack structured for auditors and executive sponsors.
Scope included
- Scoping call to agree systems, identity sources, and review windows
- Collection and normalisation of access extracts
- Mapping of standing admin, break-glass, and shared privileged accounts
- Facilitated sessions with control owners
- Written findings, remediation priorities, and signed attestation templates
Out of scope
- Continuous monitoring platforms or software licences
- Penetration testing or vulnerability scanning
- Permanent outsourced identity administration
Provider & delivery
Led by Siteridgepoint reviewers based in Nelson Mandela Bay, with remote coverage nationwide. Work can combine on-site workshops with remote evidence analysis.
Preparation
Provide current access extracts, an asset list for sensitive systems, and named control owners. Incomplete inventories extend timelines; we flag gaps early rather than inventing coverage.
Next step
Request a review with an outline of systems in scope. We reply with scoping questions and a written estimate.