Permission Audit

Noun · Security & Infosec

Definitions

  1. A review of users, groups, roles, and application rights to determine whether access is appropriate, excessive, stale, or improperly assigned. Permission audits are a core control for finding privilege creep and reducing exposure before an attacker can exploit it.

    In plain English: A review of who has what access and whether those permissions are still appropriate.

    Example: "The quarterly permission audit uncovered dormant vendor accounts that still had write access to production repositories."

Related Terms