Three IAM gaps your next audit will flag, and how Zoho Directory helps close them

Are you ready for your next audit?

If you are in IT or security leadership, "compliance" is a word you hear constantly, whether it's in audits, board meetings, or vendor pitches. But what does it actually mean when we talk about compliance in the context of identity and access management (IAM)?

At its core, IAM compliance means demonstrating that your organization controls who has access to what, how that access is verified, and what record exists of every action taken.

The frameworks that define these requirements—ISO 27001, HIPAA, PCI DSS, NIST, CJIS, and sector-specific ones like IRDAI—exist to enforce exactly that accountability.

Organizations that meet them protect sensitive data, reduce breach risk, and satisfy legal obligations more efficiently. Those that don't face failed audits, lose customer trust, and leave an open door to incidents.

So what do these frameworks actually focus on?

In this blog, we will be looking at compliance through three lenses that matter most for IAM: user lifecycle management, security controls, and monitoring.

 

USER LIFECYCLE MANAGEMENT: Knowing Who Has Access — and Who Shouldn't

Think back to the last time someone left your organization. How long did it take for their accounts to be fully deactivated? If you're not certain, you're not alone — but that uncertainty also means you're not compliant. User lifecycle management covers every point in an employee's journey — from onboarding to exit, and every role change in between.

Here's what they demand:

- Every User Needs a Unique Identity

ISO 27001, HIPAA, PCI DSS, and NIST all require that every user be assigned a unique identifier(ID). No shared accounts; every action traceable to one individual.

Covered in: ISO 27001 (5.16), HIPAA (164.312(a)(2)(i)), PCI DSS (8.2.1), and NIST (IA-2)

- Access Must Change When People Do

NIST and CJIS are explicit: when someone joins, moves roles, or exits, their access must be updated or removed immediately. Not eventually. Immediately.

ISO 27001 requires access reviews at regular intervals; PCI DSS sets the bar at a minimum of every six months. HIPAA ties reviews directly to events — a role change or termination triggers a review. Running quarterly reviews satisfies all three simultaneously.

Covered in: ISO 27001 (5.16, 9.2), HIPAA (164.308(a)(3)), PCI DSS (7.2.5), NIST (PS-4, PS-5), and CJIS (5.5.2.3)

- No One Should Have More Access Than They Need

ISO 27001, NIST, HIPAA, and PCI DSS all mandate it. NIST's Cybersecurity Framework puts it plainly: "Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties."

"Least privilege" means nobody gets more access than their job actually requires, and no single person holds unchecked control over a critical process.

Covered in: ISO 27001 (5.3), NIST (AC-5, AC-6), HIPAA (164.312(a)(1)), and PCI DSS (7.1, 7.2)

How Zoho Directory Helps

Managing the full user lifecycle manually — across every hire, role change, and exit — is where compliance gaps are most likely to form.

Zoho Directory helps make sure access changes along with role.

Conditional Assignment ensures users are given access based on predefined conditions, so when someone moves roles, their access updates automatically to reflect their new responsibilities.

Zoho Directory helps enforce least privilege across your organization.

Smart Groups lets you group users by role, department, or location, ensuring access boundaries are defined precisely, and no one has permissions that go beyond what their current function or job role requires.


Knowing who has access is only half the picture. The other half is making sure it is actually them who is trying to get in.

SECURITY: Verifying Who Gets In and Stopping Who Shouldn't

Compromised credentials remain one of the leading causes of enterprise breaches. Compliance frameworks have responded by making authentication controls a hard requirement, not a recommendation.

Here's what they mandate:

- Strong Authentication Is Non-Negotiable

ISO 27001, HIPAA, NIST, and CJIS all require Multi-Factor Authentication, especially for administrative accounts and any remote access.

MFA compliance is fully auditable and sanctionable. If your systems handle sensitive data, MFA is foundational — because even if credentials are compromised, a second factor stops the breach before it starts.

Covered in: ISO 27001 (8.5), HIPAA (164.308(a)(5)(ii)(C)), PCI DSS (8.4.1), NIST (IA-2(1), IA-2(2)), and CJIS (5.6.2.1)

- Passwords Have Rules Too

PCI DSS, HIPAA, and CJIS are all specific: minimum length, complexity requirements, expiry timelines, no reuse of recent passwords, and banned password lists. These are measurable, auditable controls that inspectors check for.

Covered in: PCI DSS (8.3.5, 8.3.6, 8.3.7, 8.3.9), HIPAA (164.308(a)(5)(ii)(D)), and CJIS (5.2.1.3)

- When Authentication Fails, the System Must Respond

HIPAA, PCI DSS, NIST, and CJIS require automatic session timeouts after inactivity and account lockouts after repeated failed attempts. If someone walks away from a workstation and leaves a session open, that's a compliance gap.

Covered in: HIPAA (164.312(a)(2)(iii)), PCI DSS (8.2.8, 8.3.4), NIST (AC-7, AC-2(5), AC-12), and CJIS (5.5.3, 5.5.5)

How Zoho Directory Helps:

Zoho Directory helps make sure a compromised password isn't enough to get in.

Multi-Factor Authentication (MFA) supports multiple authentication methods — biometrics, time-based OTPs, and QR code-based login — and can be enforced across the organization or focused on specific groups and roles.

Zoho Directory helps enforce password standards without relying on users to remember.

Password Policies lets you configure exact rules — length, complexity, expiry, reuse history — and apply them across your entire organization from one place.

Zoho Directory helps limit the damage when a session is left open.

Web Session Management handles automatic timeouts so an unattended workstation doesn't become an open door.

Zoho Directory helps control the conditions under which access is granted.

Conditional Access lets you restrict logins based on IP address, location, or time of day. If a login attempt comes from an unrecognized device in an unexpected geography, you can block it outright or require an additional authentication step.


You have governed who has access and verified how they get in. Now the question remains: can you prove it?

MONITORING: Proving It All Happened the Way It Should

When an auditor arrives, or an incident requires reconstruction, the answer lives entirely in your logs. Compliance frameworks are prescriptive here — because a control that isn't documented is a control that didn't happen.

Here's what the standards require:

- Log Everything That Matters

ISO 27001, NIST, and CJIS require detailed records of logins, admin actions, and policy changes with enough context to reconstruct exactly what happened during an incident. "Enough context" means who logged in, from where, at what time, what they accessed or changed, and whether it succeeded or failed.

Covered in: ISO 27001 (8.15), NIST (AU-2, AU-3, AU-6), and CJIS (5.4.3)

- Retain Logs and Actually Review Them

NIST and CJIS specify both retention windows and regular review requirements. CJIS suggests log reviews at least once a week, with increased frequency during elevated-risk periods. PCI DSS requires 12 months of retention. Having logs is only valuable if someone is looking at them.

Covered in: NIST (AU-11, AU-6) and CJIS (5.4.3), PCI DSS

How Zoho Directory Helps

Zoho Directory helps capture a complete record of everything that happens.

Audit Logs record the type of activity, the affected user, and timestamps across every admin action in your directory.

Identity Reports let you pull structured views of user, group, app, sign-in, and app usage data, so when an auditor asks what happened on a specific date, the answer is already there.

Additionally, Zoho Directory helps surface issues before they become incidents.

Anomaly Detection flags unusual patterns — logins at odd hours, access from new devices, unexpected user behaviour — giving your team the visibility to act before something becomes a breach.

 


 

India's Insurance Regulator Has Specific Technical Mandates — Here's What They Mean for IAM

Did you know India's insurance sector faced over 370 million malware attacks in a single year?

(reported in India Cyber Threat Report 2024 by DATA SECURITY COUNCIL OF INDIA)

IRDAI — the Insurance Regulatory and Development Authority of India — oversees every insurer, reinsurer, and intermediary operating in the country. Insurance companies hold some of the most sensitive data there is: personal details, financial records, health information. That makes them a target.

Thus, beyond financial and consumer protection rules, IRDAI has started laying down specific cybersecurity requirements too.

In March 2025, IRDAI updated those cybersecurity guidelines. The new rules get specific: how quickly you need to report an incident, how long you need to keep logs, and how your system timestamps need to work. These aren't aspirational targets — they carry high-level reporting obligations and hard deadlines.


 

Hear about Zoho Directory in practice.

BimaKavach, an InsurTech company operating in India's regulated sector, has implemented Zoho Directory as their IAM solution, using SSO, MFA, Device Authentication, and Audit Logs to meet IRDAI's requirements as they scale.

Hear directly from BimaKavach for their side of the story.

 

In Conclusion

Compliance frameworks like ISO 27001, HIPAA, PCI DSS, NIST, CJIS, and IRDAI all converge on the same three demands:

  • Control over who has access, and making sure that access changes the moment roles do, from onboarding to exit.
  • Strong verification at every login, so that even when credentials are compromised, they can't become a breach.
  • A complete, reviewable record, of every action, every access attempt, and every policy change made in your organization

Miss any one of them, and you have a gap in your security posture and in your audit trail.

Zoho Directory is built to close those gaps. From ensuring access stays aligned to roles through Conditional Assignment and Smart Groups, to adding another layer of security via MFA, along with keeping a complete record of every admin activity through Audit Logs.

Zoho Directory gives your team the controls that compliance frameworks require.


Stuck on IAM compliance? Whether you're working through specific framework requirements for your business or navigating a sector-specific mandate like IRDAI. Zoho Directory is the right place to start.

Start a free trial or Request a personalized demo and see how it works for your organization.

Comments

Leave a Reply

The comment language code.
By submitting this form, you agree to the processing of personal data according to our Privacy Policy.