ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Easy
A security auditor discovers that several former employees still have active accounts on various internal systems, and their access has not been revoked. This oversight poses a significant security risk. Which aspect of the identity and access provisioning lifecycle has failed?
- AReview
- BDeprovisioning (Revocation)
- CProvisioning
- DAuthentication
Show answer & explanationAnswer & explanation
Correct answer: B. Deprovisioning (Revocation)
Deprovisioning, also known as revocation, is the process of removing user access and accounts when they are no longer authorized (e.g., due to termination or role change). The scenario clearly describes a failure in this process.
Why the other options are wrong
- A. Review is the periodic checking of access rights, which might have detected the issue but is not the direct failure of removal.
- C. Provisioning is the initial granting of access, which is not the issue here as accounts were created correctly.
- D. Authentication is verifying identity, which is not the root cause of former employees retaining access.
Deprovisioning (Revocation)
The process of removing a user's access rights and accounts from systems and applications when they are no longer authorized.
- Crucial for security hygiene.
- Often triggered by termination or role change.
- Prevents unauthorized access by former personnel.
Memory trick: PACE: Provision, Access, Certify, Exit