Joining, changing and leaving.
WHAT THE LIFECYCLE IS
Account created on joining Access granted per role Access changed on role change Access removed on leaving
WHERE IT FAILS
Access granted and never reviewed Role changes adding access without removing the old Leaving processes covering only obvious systems
WHAT TO ESTABLISH FOR JOINING
What access the role requires, defined in advance Who approves it That it is granted rather than copied
WHY NOT COPIED
Copying an existing person's access propagates whatever they accumulated.
WHAT TO ESTABLISH
Standard access profiles per role.
WHAT THAT PROVIDES
Consistency, and a basis for review.
WHAT TO ESTABLISH FOR ROLE CHANGES
That old access is removed as new access is granted.
WHY IT IS MISSED
Adding is requested; removing is not.
WHAT TO ESTABLISH
Review of access at every role change.
WHAT TO ESTABLISH FOR LEAVING
A checklist covering every system Removal on the last day Verification that it was done
WHY ON THE LAST DAY
Delay leaves exposure open, and it is the standard failure.
WHAT THE CHECKLIST SHOULD COVER
Email and core systems Financial systems and banking Remote access Physical access and keys Mobile devices Shared credentials, which must be changed Accounts on external services Anything registered in their name
WHY SHARED CREDENTIALS MUST BE CHANGED
Removing a person does not remove their knowledge of a shared password.
WHAT TO ESTABLISH ABOUT ABRUPT DEPARTURES
That access can be removed immediately.
WHY
Departures are not always planned.
WHAT TO RECORD
What was removed and when.
WHAT TO VERIFY PERIODICALLY
That leavers no longer have access anywhere.