← ISC2 CC: cybersecurity foundations in practice
03 / 5 · 35 MIN

Identity and access lifecycle

Review permissions on joining, changing roles, and ending activities.

Concept and mechanism

The identity lifecycle includes creation, role assignment, review, and access removal. A team move is a review event rather than merely an opportunity to add permissions. Confirm current need and remove what is no longer justified. Least privilege limits authority to what is needed; separation of duties addresses combinations that should not belong to one person. If an order requires different creator and approver, clicking twice or using a shared account does not satisfy the rule. Enforcement belongs in the workflow with attributable identities. RBAC organizes permissions through roles; attribute-based models can consider other characteristics and context according to design.

Guided application

In a fictional example, someone moves into APS while a reporting bot still uses their identity. Review human privileges and identify automation ownership, purpose, and dependencies before revocation or reassignment. A technical account also needs duration, control, and closure when it no longer serves a purpose. Do not solve continuity by sharing personal passwords. In authentication, count proof types rather than screens: a password and memorized PIN sent to the server are both knowledge. This differs from a local PIN activating a physical authenticator whose protocol can prove possession. The distinction prevents classifying any second field as MFA. At review closure, record what was removed, what remains, and its approved justification.

IN PRACTICE

Role move: review need, remove old privilege, and handle dependent automation.

Common pitfalls

Two passwords as two factors; move as accumulated roles; ownerless bot; logs as self-approval prevention.

Related topics: Security principles and conduct · Governance, continuity, and awareness · Networks, cloud, and boundaries

Take this idea with you

Keep identity, need, and responsibility aligned throughout the lifecycle.

Create account

Reference: Security and privacy controls · CC examination outline effective 2026-09-01; PDF v01/2026