A secure record is maintained for the life of systems and their resources that covers the following for each user:
- their user identification
- their signed agreement to abide by system usage policies
- who authorised their access
- when their access was granted
- the level of access they were granted
- when their access, and their level of access, was last reviewed
- when their level of access was changed, and to what extent (if applicable)
- when their access was withdrawn (if applicable).