The asset owner shall have policies and procedures for assigning, reviewing and removing access rights to/from IACS-specific roles and users.