ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A cybersecurity team is conducting an audit of user permissions across all critical systems. They discover that several employees who have transferred departments or left the company still retain active accounts or elevated privileges in their old systems. This situation indicates a failure in which critical aspect of access control lifecycle management?

  1. AProvisioning
  2. BAuthentication
  3. CDeprovisioning
  4. DAuthorization
Show answer & explanation

Correct answer: C. Deprovisioning

Deprovisioning is the process of revoking or removing user access rights and accounts when an individual's role changes or they leave the organization. The scenario describes a failure to remove access for transferred or departed employees, directly pointing to a deprovisioning issue.

Why the other options are wrong

  • A. Provisioning is granting initial access, not revoking it when roles change or employees leave.
  • B. Authentication is verifying identity, not managing the lifecycle of access rights.
  • D. Authorization is defining what an authenticated user can do, not the process of account removal.

Deprovisioning

The process of revoking or removing a user's access rights and accounts when their role changes, they leave the organization, or their access is no longer required.

  • Crucial for security to prevent unauthorized access.
  • Should be timely and thorough.
  • Part of the access control lifecycle.

Memory trick: Deprovisioning is like cleaning out the closet when someone moves out.

More Access Controls Concepts questions