Cyber Security Act 2021 Compliance

Identity, Access Management & Offboarding Compliance

Barakat helps employers identify every active account, centralise identity control, revoke access cleanly when staff leave, and maintain ongoing oversight in a way that supports Section 55 of Sierra Leone's Cyber Security and Crime Act, 2021 and reduces the wider management and corporate exposure addressed in Section 56.

Access that stays under control

For many organisations, access sprawl does not look dramatic until an ex-employee still has a login, a contractor account never expired, or a privileged mailbox remains active without review. This engagement turns account ownership, offboarding, and oversight into a clearer control system instead of a last-minute scramble between HR and IT.

Legal anchor

Section 55 of Sierra Leone's Cyber Security and Crime Act, 2021 requires an employee, upon disengagement from employment, to relinquish or surrender all codes and access rights to the employer within a reasonable time. That makes offboarding more than an internal HR checklist. It is a direct control obligation touching accounts, passwords, tokens, VPN access, devices, Wi-Fi credentials, and any other access path still tied to the person who has left.

Section 56 extends the issue beyond the departing employee. It provides for liability where a person exercising management or supervisory authority fails to exercise reasonable and proper control, and it also exposes the legal person where an offence occurs because of lack of supervision or control. In practice, access governance, leaver controls, and account oversight are part of how management shows that reasonable control exists.

Best for

Banks NGOs Hospitals Microfinance Law Firms Corporates

Best suited to employers that rely on multiple systems, shared services, remote access, or fast staff turnover and want stronger control over who still has access to what, when, and why.

Deliverables

  • Access management policy
  • Offboarding checklist
  • Monthly access audit reports
  • Access register

Control focus

  • Full account inventory across identity systems, email, cloud services, Wi-Fi, VPN, and physical access
  • Central identity control with MFA, contractor expiry, and cleaner privilege discipline
  • Timestamped offboarding steps that revoke access consistently when staff leave
  • Monthly reporting, anomaly review, and real-time support for urgent departures
Access Audit

Find every account before orphaned access becomes a live risk

Most access-control failures start with incomplete visibility. If no one can confidently list every active account, privileged identity, remote-access path, or shared credential, offboarding will always be inconsistent. We begin by making the identity landscape visible and cross-checking it against the current staff reality.

Pull a list of user accounts across Windows Active Directory, Barakat software modules, email, cloud services, Wi-Fi, VPN, and physical access codes
Cross-reference those accounts against the current staff list to identify orphaned accounts, stale contractors, duplicate identities, shared logins, and users with unnecessary privilege
Capture last login dates, privilege levels, account purpose, and ownership gaps so management can see which access paths need urgent cleanup first
Placeholder illustration for enterprise account inventory and access audit work
Implementation

Use one clearer control point instead of scattered identity decisions

Once the account map is clear, the next step is tightening how access is granted and revoked. We help organisations move away from fragmented administration by using a stronger identity source, documenting lifecycle rules, and enforcing extra protection where compromise would matter most.

Configure Active Directory as the primary control point where appropriate and link Barakat software modules and other connected services to it for cleaner account administration
Set contractor account expiry rules, reduce unnecessary privilege, and define role-based access so temporary access does not quietly become permanent
Implement MFA on email and remote access so a single compromised password is less likely to become a full account takeover
Placeholder illustration for identity control, MFA, and account governance implementation
Offboarding Control

Revoke access methodically when someone leaves, not after the fact

The riskiest offboarding failures are often simple ones: a mailbox still active, a VPN token still usable, a Wi-Fi password unchanged, or a finance system account that no one remembered. We design a practical offboarding workflow so revocation is immediate, documented, and repeatable under real operational pressure.

Create a documented offboarding checklist with timestamped revocation steps covering email, Active Directory, business applications, cloud services, Wi-Fi, VPN, physical access, and shared credentials
Define who approves the exit action, who executes each revocation task, and how completion is recorded so the process is accountable instead of assumed
Build the process so urgent dismissals, contractor exits, and ordinary staff departures can all be handled without leaving hidden access behind
Placeholder illustration for offboarding workflow and timestamped access revocation
Ongoing Oversight

Keep reviewing access so control does not degrade after the cleanup

An access project loses value quickly if it ends with a one-time cleanup. We help organisations maintain a recurring view of who still has access, how long they have had it, what privilege they hold, and which anomalies need review before they become the next control failure.

Produce monthly access reports showing active accounts, last login dates, privilege levels, and anomalies that need management attention
Maintain an access register that becomes the master reference for who has access to what across the organisation
Provide real-time offboarding execution support when clients call to say someone is leaving and access must be revoked without delay

Deliverables: Access management policy, offboarding checklist, monthly access audit reports, and an access register showing who has access to what.

Urgency: If an ex-employee, expired contractor, or forgotten admin account could still sign in today, the organisation is carrying a live control failure that should be closed before it turns into a breach, dispute, or management problem.

Book Access Control Review
Placeholder illustration for monthly access oversight and anomaly review

If former staff can still sign in, the offboarding gap is already real

We can inventory the accounts, centralise the control point, tighten the offboarding workflow, and give management a clearer view of access before the next departure exposes a weakness you should already have closed.

Request a Compliance Review