risk
Weak account provisioning/de-registration and access review
No formal user registration/de-registration procedure and no periodic access-rights review, so orphaned or excessive accounts accumulate and access is not revoked when roles change or personnel leave.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Access Control & Identity Management
- taxonomy
- iso-27005-vulnerability
- inherent_rating
- high
Details
- risk_id
- access-provisioning-review-gap
- category
- cyber_security
- likelihood
- high
- impact
- medium
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-vulnerability
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle mitigates Weak account provisioning/de-registration and access review
- strength
- primary
- rationale
- Owner-approved provisioning with role-based entitlements and 1-business-day deprovisioning on termination directly eliminates orphaned accounts and un-revoked access.
- UC-ACCESS-06 — Manage unique identities and identifiers end to end mitigates Weak account provisioning/de-registration and access review
- strength
- related
- rationale
- Prompt deactivation of identifiers no longer needed supports timely de-registration.
- UC-ACCESS-02 — Review user access rights periodically mitigates Weak account provisioning/de-registration and access review
- strength
- primary
- rationale
- Periodic owner recertification of user and privileged access is the direct detective control for the missing access-review element of this risk.