CISSP Identity Lifecycle Management: The Account You Forgot Is the One That Gets You
The exact 3-phase system that stops forgotten accounts, passes audits, and answers any IAM exam question, straight from my work as a cybersecurity manager.
Imagine you have a company. Everything is set up.
You have brilliant access management, you label all the data, and everything is a well-oiled machine.
But you forgot one small detail. You forgot how to handle accounts when people leave.
Or maybe you forgot to review the accounts once in a while, and now you have a couple of employees who have access to more sensitive information than the CEO.
The whole identity lifecycle can be very tricky, and ignoring its risks can easily destroy the security posture of your organization.
Remember: A forgotten account is like an invitation for an attacker.
Here is what you’ll learn in today’s article:
Why identity and access management is so problematic in real organizations
The full IAM lifecycle - phase by phase
How access control, compliance, and configuration management hold the middle together
Why is deprovisioning the most neglected control in security
The key CISSP takeaways you need for the exam and the real world
Let’s get into it.
The problem nobody wants to own
Before we dive into details of how to handle accounts, let me tell you what’s the most problematic thing about it from my experience.
Nobody wants to own this problem.
Everyone loves the beginning. A new hire joins, IT creates the account, access is granted, and everyone feels productive.
But the rest of the lifecycle? Silence.
Nobody wants to review access every quarter.
Nobody wants to untangle the permissions an employee collected over five years.
And nobody remembers to remove access the day someone walks out the door.
IT assumes the manager will flag it.
The manager assumes IT takes care of it.
Everyone assumes there’s a process.
And the account just sits there. Alive. Long after the person is gone.
That’s the real issue. Identity lifecycle management isn’t hard because the technology is complicated. It’s hard because it’s boring, it never ends, and it belongs to everyone and no one at the same time. At least that’s what people think.
So remember this: the manager owns their team's accounts. Not IT.
IT just configures access based on the rules they're given. That's where their job ends.
So how do you fix a problem everyone ignores?
You stop treating access as a one-time event and start treating it as a lifecycle.
Break it into phases, and “someone should handle this” becomes “this phase, this owner, this action.”
That’s how forgotten accounts stop happening. Let’s break it down.
Before we start: Do you want to see privilege creep in action? I built a free interactive tool where you run an access review yourself and watch how fast permissions pile up.
The IAM Lifecycle, Phase by Phase
Every identity in your organization moves through the same lifecycle. Understanding each phase, and the controls that belong to it, is what separates a security professional from an administrator.
The lifecycle looks like this:
The beginning and the end get attention. The red area is where it gets problematic.
Think you already know how the identity lifecycle works? Prove it. I put together a quick quiz on everything in this article. Drop your score in the comments!
Provisioning: Creating and Granting the Identity
Provisioning is the creation of a user’s digital identity and the assignment of their initial access, typically on day one.
This phase usually works. It has a clear trigger, a new hire or an HR record, and it’s often automatic. That’s exactly why it rarely gets forgotten.
The one rule that matters: least privilege. Grant only what the role needs, nothing more.
CISSP note: When access is technically functional but excessive for the role, the correct answer favors restricting access from the start, not granting broadly and correcting later.
The Problematic part between the beginning and the end
Okay, hooray. We have the account, the person happily uses it. So where’s the problem?
The problem is that nothing stays still.
The account was perfect on day one. But people don’t stay on day one. They get promoted, switch teams, join a project and leave it.
Every one of those changes is supposed to update their access, and too often, it doesn’t.
This is the maintenance phase, the longest stretch of an identity’s life. It’s where access control, compliance, and configuration management all live.
But if you remember one thing from this section, make it this:
Access must be reviewed periodically.
Not once. Not “when we get around to it.” On a schedule.
Because even the best processes won’t prevent all mistakes, and without regular reviews, nobody removes old access.
Five years later, you’ve got an employee who moved through three departments and kept every permission from all of them.
On paper, they’re in operations. In reality, they can still touch finance, HR, and systems from a role they left in 2021.
That’s called privileged creep, and periodic reviews are the one control that catches it before it becomes an audit finding or a breach.
Two rules make reviews actually work:
They run on a fixed schedule (quarterly, annually)
The manager or data owner conducts the review, never the user.
Remember: In this phase, the danger isn’t the access you grant. It’s the access you forget to take away.
Deprovisioning: This is where it ends
Every account has a last day. The problem is you don’t often know it’s the last day.
What if a contractor finishes the project and nobody tells the IT department? Or an employee is fired, but the manager didn’t trigger the right workflow?
That’s how the account just sits there. Alive. And a dormant account with nobody watching it is exactly what an attacker is hoping to find.
The fix is simple, and it’s the same one that fixes half of this lifecycle: automation.
When HR marks someone as terminated, the system should kill their access everywhere, instantly.
And as I was saying before, back it up with periodic checks for orphaned accounts that slipped through.
CISSP note: When a scenario describes a terminated employee who still has access, the answer is almost always automated deprovisioning tied to HR, not a manual step someone has to remember.
Remember: The most dangerous account isn’t the one you’re watching. It’s the one you forgot existed.
Key Takeaways
Identity and access management isn’t hard because it would be a complex technical issue.
It’s hard because it never ends, and someone has to own every phase. Here’s what to walk away with - best practices for the exam and for the real world:
Treat access as a lifecycle, not an event. Provisioning, maintenance, deprovisioning. Every phase needs an owner, or accounts fall through the cracks.
The manager owns the accounts, not IT. IT configures based on the rules it’s given. Accountability sits with the manager or data owner.
Provision with least privilege. Grant only what the role needs. Excessive access is a risk from day one, and the CISSP answer is always to restrict from the start.
Review access on a schedule. Periodic reviews are the one control that catches privilege creep before it becomes a breach. The manager reviews, never the user.
Deprovision automatically. Tie revocation to HR so access dies the moment someone leaves. The account you forget is the one that gets you.
Master these five, and you’ll read any IAM exam scenario, spot the phase that failed, and pick the control that reduces risk. That’s exactly how the CISSP wants you to think, and what serves me in my role.
Now test yourself. You just learned the full identity lifecycle. See if it stuck with a quick quiz on provisioning, maintenance, and deprovisioning. Score 8/10 or better and you're on solid ground for the CISSP.
What to Read Next
If this clicked, here’s where to go from here on Decoded Security:
The AAA Framework: Can Your Coworkers Log In as You? The identification, authentication, and authorization concepts behind every access decision in this article, explained the same simple way.
Start Here: The Decoded Security Roadmap New to cybersecurity or on the CISSP path? This is the map. It shows you exactly what to focus on so you stop drowning in scattered material.
GRC for Beginners: The Exact Study Plan Want to turn these governance and risk concepts into a real career direction? Start with this.
Pick one, keep the momentum, and you’ll build real understanding instead of collecting random facts.
Let’s Connect
If you want to collaborate, discuss, or just geek out over networking and cybersecurity, reach out:
Email: erich.winkler@decodedsecurity.com
LinkedIn: Erich Winkler
Gumroad community: Decoded Security
Start Here: Decoded Security Roadmap
Enjoyed this article? Like it or drop a comment. I’d love to hear your thoughts and questions!
Let’s learn and grow together!





