risk

Weak account provisioning/de-registration and access review

No formal user registration/de-registration procedure and no periodic access-rights review, so orphaned or excessive accounts accumulate and access is not revoked when roles change or personnel leave.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

category
cyber_security
domain
  • Access Control & Identity Management
taxonomy
  • iso-27005-vulnerability
inherent_rating
high

Details

risk_id
access-provisioning-review-gap
category
cyber_security
likelihood
high
impact
medium
inherent_rating
high
treatment
mitigate
taxonomies
  • iso-27005-vulnerability

Source

No record-specific source URL is provided.

Connections