The formal policy/procedure should be established and described the topics as follows:
- review unused IDs on application every 90 days
- review user profiles on application at least twice a year
In addition, the formal policy/procedure should be approved by Management and communicated to the relevant staff.
A regularly review of profiles and unused IDs on application should be performed. In addition, evidence of the review and approval should be prepared and maintained for reference.