Define the identity that persists through transition
In a fictional payments service, Ana has a work account and an administrative account. A directory display name is insufficient to link them reliably: names can coincide or change. Define stable identifiers and rules connecting people, accounts and systems. The exercise stores people and accounts separately, with SQL constraints preventing duplicate account identities or references to nonexistent people. This tests fixture consistency, not anybody’s actual identity. In an IAM project, request evidence about the relationship’s origin and the resolution of ambiguous matches. Service accounts need their own identity and management responsibility; they should not be artificially turned into employees to fit an HR import.
Treat entry, transfer and departure as verifiable states
At onboarding, confirm the authorized relationship and role-required access before provisioning. During a transfer, compare old and new access: adding the new group without reviewing earlier groups can accumulate incompatible privileges. Temporary overlap for knowledge transfer needs explicit purpose, ownership and an end time. At departure, identify affected systems and credentials, including paths independent of the central directory. The lab represents Carla as departed, but her account remains enabled in the observed-state table. Local policy denies use and reconciliation retains an unresolved finding. The computed denial did not disable an external provider account. Handover should distinguish a received event, dispatched work, applied change and observed outcome.
Retain uncertainty during reconciliation
Duarte’s employment state is unknown because the source supplied no usable state. The model does not convert that value to active. It also does not declare him terminated: the finding requires source clarification and a decision under applicable policy. A real system must define responses to missing, delayed or contradictory data, balancing exposure and continuity through explicit authority. Retain origin, observation time and integration errors. A difference between HR and an application may result from delay, incorrect association or execution failure; do not select a cause solely from the divergent-record count. Compare expected and observed populations, keep unassociated accounts visible and avoid silently excluding rows that could not be processed.
Separate the different access deadlines
Eva has a temporary account until 12:00 UTC, group membership until 11:00 and a direct read grant until 11:30. At 11:00 she loses group-derived payment preparation but can still read reports through the independent grant. That read expires at 11:30; at 12:00 the account itself becomes ineligible. The exercise uses a local convention with no modeled start time and an exclusive end: at expiry, the corresponding access is already inactive. Instants with different offsets are normalized for comparison; timezone-free values are rejected. These deadlines are fictional, not universal NIST limits. Test each layer and establish whether the application uses current state or an earlier session or cache. The lab does not measure distributed propagation.
Manage service identities without assumption-driven outages
Batch-service reads reports and has Bruno as owner; it has no person association pretending to be a human user. When Bruno becomes departed, the fixture reports service-owner-not-active and considers the account ineligible under its local policy. This demonstrates an accountability gap, not a recommendation to automatically stop a production batch when its owner changes. The organization needs a process to transfer responsibility, review purpose, credentials, privileges and dependencies, and decide proportionate measures. An unowned account should neither disappear from inventory nor be assigned to an arbitrary person. For APS, provide consumer lists, rotation and recovery procedures and evidence that the successor accepted responsibility. Also define who follows provisioning failures outside normal hours.
python3 content/labs/cissp-identity-lifecycle/run.py --output /tmp/cissp-identity.json
# In-memory SQLite only; no HR, directory or production account changes.At 11:00 UTC, Eva loses group-derived preparation but retains direct reading until 11:30. These are distinct permissions and deadlines.
Common pitfalls
Name as identity; unknown as active; completed ticket as disablement; service account treated as an employee.
Related topics: Identity lifecycle · Effective privileges and review · Separation of duties
A transition is established through relevant states and observed access in in-scope systems.
Reference: Security and Privacy Controls for Information Systems and Organizations · CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29