Control Statement
All access held by a departing or suspended individual shall be removable in a single action, within a period measured against the tempo at which that access could be misused.
Purpose. To close the window between a person ceasing to be trusted and their access ceasing to work.
Discussion
Two properties are being required, and they fail independently. *Single action* fails when access exists outside the primary identity provider — local accounts, SaaS applications provisioned outside single sign-on, VPN credentials, API keys, shared secrets — each of which survives a correctly executed identity-provider disablement. *Within tempo* fails when the process is complete but slow: a revocation that takes four days is not a control against access that could be misused in twenty minutes. The tempo comparison is what connects this control to the TA family, and the period should be derived from what the access could do rather than from what the offboarding process currently achieves.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Measured elapsed time from separation trigger to full access removal
- Number of systems requiring separate manual revocation
- Stated revocation period compared against the time in which the access could cause material harm
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- WF-2 Privileged Human RegisterPrivileged human register identifying what each individual holds
- WF-4 Insider Risk PositionSuspension decisions requiring immediate revocation
- Outside the frameworkHuman resources separation and suspension triggers
- ID-2 Credential Strength and BindingNon-human secret inventory that scopes revocation on separation
Produces
- TM-7 Terrain OwnershipOwnership reassignment required before revocation orphans an element
- WF-2 Privileged Human RegisterRegister update following removal
- CE-5 Remediation Backlog PrioritizationSystems outside single-action revocation entering the backlog
- DV-5 Device Lifecycle and SanitizationSeparation triggers that start the trust-removal clock
Activities
- L2Define the revocation process for departing and suspended individuals.
- L2Measure the elapsed time from trigger to complete revocation.
- L2Raise a finding where measured time exceeds the stated period.
- L3Derive the required period from the tempo at which the access could be misused, not from current process capability, with provenance per GA4.
- L3Enumerate every access location outside the primary identity provider and bring each into the single revocation action or record it as an exception.
- L3Distinguish planned departure, immediate separation and suspension, since the tempo requirement differs sharply between them.
- L3Verify revocation by testing the access rather than by confirming the ticket closed.
- L4Trend measured revocation time by separation type against its required period.
- L4Measure surviving access found by post-revocation testing, which is the direct measure of the single-action property.
- L5Reduce the number of access locations outside the primary identity provider, since consolidation improves this control more durably than accelerating the process that compensates for fragmentation.
Measurement
Measured revocation time by separation type against required period.
Surviving access found by post-revocation testing.
Evidence and Assessment
Measured revocation times from exercise or real separations; exception register; post-revocation verification results.
Test a revocation end to end against the stated tempo; examine for access surviving in systems outside the primary identity provider; test whether verification tests access or only confirms process completion.
Related Guidance
- PS-4
- PS-5
- AC-2(3)
- PR.AA-01
- GV.RR-02
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.2 of 17 techniques — M8.14, M8.17
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.1 of 20 techniques — M3.19
Terrain It Is Named On
- T7WorkforceSeparation and revocation tempo, the other half of the decisive point.
Artifacts It Stands On
- producesSeparation and revocation recordHow long it takes to remove everything an individual holds, per system, and which systems cannot be revoked in a single action. Feeds terrain ownership so revocation does not orphan an element.
- consumesPrivileged human registerWhich individuals hold which high-consequence access, reconciled against the identity system rather than against the last access review spreadsheet.
- consumesInsider risk positionThe stated position on insider risk: what may be done, by whom, under what legal, privacy and labor-relations constraints, and how a case is dispositioned.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.