access-control-review

Review access control risks and segregation of duties against FFIEC, NIST, and SOX standards.

1|1|Updated Feb 19, 2026
One-click install
npx skills add https://github.com/GoldenZero/skills --skill access-control-review-goldenzero
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: access-control-review
Source: https://github.com/GoldenZero/skills/tree/main/skills/access-control-review
Command: npx skills add https://github.com/GoldenZero/skills --skill access-control-review-goldenzero

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes assets (resource) and references (resource) and scripts (resource) components.

What problem does it solve?

This Skill helps identify and remediate risks related to user access, privileged accounts, and segregation of duties (SoD) in financial institutions, ensuring compliance with regulatory requirements.

Core Features & Use Cases

  • Access Governance Assessment: Evaluate access controls against FFIEC, NIST, and SOX standards.
  • Lifecycle Management Review: Assess provisioning, modification, and de-provisioning processes.
  • SoD Conflict Analysis: Identify toxic combinations and assess compensating controls.
  • Use Case: A bank needs to prepare for an FFIEC audit. This Skill can analyze their current access control policies, user access logs, and SoD rules to identify any gaps and provide actionable recommendations for remediation.

Quick Start

Use the access-control-review skill to check my access control for gaps risks and required fixes.

Frequently Asked Questions about access-control-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review access controls and SoD conflicts for FFIEC compliance?

Access control review evaluates user access provisioning, privileged accounts, and segregation of duties conflicts against FFIEC and SOX requirements. It analyzes access data, SoD matrices, and process documentation to identify toxic combinations and verify compensating controls.

What do I need to assess segregation of duties risks in financial institutions?

Assessing segregation of duties risks requires access data, SoD matrices, application inventories, and process documentation. Analyzing these inputs identifies toxic combinations and evaluates whether compensating controls adequately mitigate SoD conflicts.

Can I use this to prepare for a SOX access certification audit?

Yes, access certification review checks user provisioning and de-provisioning processes against SOX controls and COSO principles. It analyzes application inventories and access logs to identify compliance gaps and provide actionable remediation recommendations.

How does access governance assessment work with NIST Cybersecurity Framework?

Access governance assessment maps user access controls and lifecycle management processes to NIST Cybersecurity Framework standards. It evaluates provisioning and modification workflows to detect privileged access risks and ensure compliant access certification.

What is the best way to identify toxic combinations in user access provisioning?

Identifying toxic combinations requires cross-referencing access data with SoD matrices to detect segregation of duties conflicts. The review process analyzes provisioning workflows and application inventories to flag incompatible permissions and assess compensating controls.

Does access control review evaluate privileged access lifecycle management?

Yes, access control review evaluates privileged access lifecycle management by assessing provisioning, modification, and de-provisioning processes. It analyzes access data against FFIEC and NIST standards to identify gaps in privileged account governance.