ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsEasy

A security auditor is reviewing the effectiveness of an organization's access control system. The auditor discovers that several former employees still have active accounts with full access privileges to critical systems. Which access control concept has been most clearly violated in this scenario?

  1. AAccess review
  2. BDeprovisioning
  3. CAuthorization
  4. DIdentification
Show answer & explanation

Correct answer: B. Deprovisioning

Deprovisioning is the process of removing or disabling a user's access when they leave an organization or no longer require specific privileges. The scenario directly describes a failure in this process.

Why the other options are wrong

  • A. Access review is checking current access, but the fundamental failure is the lack of deprovisioning for former employees.
  • C. Authorization determines what an authenticated user can do, which is still active due to failed deprovisioning.
  • D. Identification is asserting who someone is, not managing their access after departure.

Deprovisioning

The process of revoking or disabling user access to systems and resources when they no longer require it, such as upon termination or role change.

  • Crucial for maintaining security after employee turnover.
  • Prevents unauthorized access by former personnel.
  • Often includes disabling accounts, removing group memberships, and reclaiming physical access cards.

Memory trick: From hiring to firing, access changes are key.

More Access Controls Concepts questions