PDF p.97
In progress
User Account Provisioning
Summary
PDF p.97User account provisioning involves setting up accounts for new employees, consultants, contractors, and sometimes customers. The process includes identity proofing, issuing credentials, providing hardware and software, teaching policy awareness, and assigning permissions. Deprovisioning removes access rights when an employee leaves or a project ends.
In plain words
Supplementary — not from your PDFProvisioning sets up a new person: confirm who they are, create their account and credentials, give them equipment, train them on the policies, and grant the right access. Deprovisioning removes it all when they leave.
Detailed explanation
PDF p.97-
Provisioning Process
-
Identity Proofing
- Verification: Confirms the person's identity using official documents and records.
- Background Check: May include checks on addresses, education, employment history, criminal record, and credit issues.
-
Issuing Credentials
- Password Selection: Allows users to choose a password known only to them.
- Authenticator Enrollment: May include biometric or token-based authenticators.
-
Issuing Hardware and Software Assets
- Resources: Typically includes a computer, smartphone, and licensed software apps.
- Shadow IT: Ensures employees have adequate resources to avoid unauthorized procurement.
-
Teaching Policy Awareness
- Training: Provides training and access to learning resources on security policies and risks.
- Personal Use Policies: Educates on policies for personal use of IT assets.
-
Creating Permissions Assignment
- Role Identification: Determines work roles and configures appropriate rights.
- Monitoring: Tags accounts with privileged access for close monitoring.
-
Identity Proofing
-
Deprovisioning Process
- Access Removal: Removes access rights and permissions when an employee leaves or a project ends.
- Account Management: Disables or deletes accounts as necessary.
Important terms
taken from the text above- Background Check
- May include checks on addresses, education, employment history, criminal record, and credit issues.
- Password Selection
- Allows users to choose a password known only to them.
- Authenticator Enrollment
- May include biometric or token-based authenticators.
- Resources
- Typically includes a computer, smartphone, and licensed software apps.
- Shadow IT
- Ensures employees have adequate resources to avoid unauthorized procurement.
- Training
- Provides training and access to learning resources on security policies and risks.
- Personal Use Policies
- Educates on policies for personal use of IT assets.
- Role Identification
- Determines work roles and configures appropriate rights.
- Access Removal
- Removes access rights and permissions when an employee leaves or a project ends.
- Account Management
- Disables or deletes accounts as necessary.
Examples & real-world scenarios
Supplementary — not from your PDF- Checking ID documents before creating an account.
- Issuing a laptop and enrolling the user in MFA.
- Disabling the account on the employee's last day.
Scenario
A contractor's project ends, but nobody tells IT, and their VPN account stays active for six months. A deprovisioning process tied to contract end dates prevents this.
Common mistakes
Supplementary — not from your PDF- Forgetting deprovisioning. It matters as much as provisioning.
- Skipping identity proofing for 'urgent' new starters.
Practical skills
Supplementary — not from your PDF- Write an onboarding and offboarding checklist.
What I should remember
Key Points PDF p.97-
Provisioning Process
- Identity Proofing: Verifies identity and may include background checks.
- Issuing Credentials: Password selection and authenticator enrollment.
- Hardware and Software: Provides necessary resources.
- Policy Awareness: Training on security policies and personal use.
- Permissions Assignment: Configures rights based on roles and monitors privileged access.
-
Deprovisioning Process
- Access Removal: Removes rights and permissions.
- Account Management: Disables or deletes accounts.