Disable and Deprovision

All user identities come to an end. Human users may leave the organization, or so change their association with it that their systems identity should not be left active. (Death, of course, may lead to their systems identity being disabled and then deprovisioned as well). Nonhuman users may be decommissioned and removed from active use. We'll be looking at this idea in more detail further in the course. Management decisions may also dictate that an employee's identity be temporarily disabled or precluded from use when they separate from the organization or are believed to be under stress, duress, or impairment. Security professionals should work with their organization's personnel or human resources departments to ensure that procedures are in place to support prompt disablement of accounts when required.

2 slides · 1 min read · Domain 5

Slide 1

Deprovisioning propagates the deactivation of permissions throughout the systems. Note that accounts are not deleted but disabled. The data custodian or other identity and access management administrators perform these tasks.

Test this domain