Quarterly LastPass Information and Access Audit

Purpose and Frequency

Ensure the password manager contains only current client information and that each person has access only to accounts required for their role. Perform quarterly and whenever a client, employee, or contractor relationship ends.

Audit Steps

  1. Compare records with the active-client list; identify obsolete former-client information, verify retention requirements, remove approved obsolete records, and document the action.

  2. Compare users with the current team roster; remove former or unassigned users and confirm current users have only role-required access.

  3. Remove duplicate, outdated, or test credentials after verification. Confirm credentials are in the correct restricted client folder and administrative permissions are limited.

  4. Complete routine corrections within three business days. Remove former-employee or unauthorized access immediately.

  5. Report suspected credential exposure immediately and change affected passwords through the approved process.

Documentation

Record audit date, client/system reviewed, issue, access or information removed, assignee, completion date, and verifier. Never record actual passwords or other secrets in the audit record.

Completion Standard

All users and client records have been reviewed, corrections are documented, and unresolved risks have been escalated and verified.


Was this article helpful?