16.7: Establish Process for Revoking Access
- Critical Security Controls Version 8:
- 6.2: Establish an Access Revoking Process
Establish and follow an automated process for revoking system access by disabling accounts immediately upon termination or change of responsibilities of an employee or contractor . Disabling these accounts, instead of deleting accounts, allows preservation of audit trails.
[csf.tools Note: For more information on the Critical Security Controls, visit the Center for Internet Security.]