Insider risk · 3.4

The fortnight around a departure

The fortnight around a departure. What the requirement says, what it means in practice, and what an assessor will ask.

For an independent reference point, see CISA insider-threat mitigation resources.

The window

From resignation to the last day, and a while after

Research on data movement around departures consistently finds elevated activity in the weeks before somebody leaves. Most of it is ordinary: people gather their own work, examples of what they have done, contacts, things they consider theirs.

Some of it is not, and the two look similar in a log, which returns to the entry on what detection establishes.

The list

What has to happen on the last day

A written list, maintained, covering every system: accounts disabled, tokens revoked, physical access removed, devices collected, shared credentials the person knew changed, external services the company pays for reassigned.

The last two are the ones that fail. Shared credentials survive departures indefinitely, and the software account nobody knew about surfaces at renewal.

Before the conversation

For involuntary departures, plan first

Where an employment relationship is ending on the employer's initiative, the revocation should be prepared before the conversation and executed at an agreed moment.

This is ordinary practice, it is not an accusation, and it should be the same procedure for everybody so that applying it does not communicate suspicion about a particular person.

Notice periods

The awkward middle

Somebody who has resigned may work for weeks with full access. The options are to leave access unchanged, to reduce it to what the remaining work requires, or to end the working period early.

All three are legitimate and the middle one is usually right. Doing it as a stated policy applied to everybody avoids the situation where reducing one person's access is read as an allegation.

Proportion

Most leavers are not a problem

A departure process that treats every leaver as a suspect is unpleasant, damages the relationship with people who may return or refer others, and is disproportionate to what actually happens.

Consistency is what makes it acceptable: the same steps for everybody, explained as routine, applied to the chief executive as to the newest starter.

The review

Looking at recent activity, proportionately

A review of file activity in the notice period is reasonable where the role warranted access to controlled information. What it should produce is either nothing or a question, and the threshold for the question should be set before anybody looks.

Reviewing selectively, on suspicion, without a stated policy, is the arrangement most likely to go wrong in every direction at once.

Records

What to keep

The checklist, completed, with dates and the name of whoever did each item. Retained.

An assessor will ask how you know access was removed, and a completed checklist is the answer. An assurance that it is always done is not.

Transfers

The internal move nobody offboards

Somebody changes role and keeps the access from the old one. Repeated over several years this produces individuals with rights nobody would grant them today.

Apply the departure checklist to internal moves, removing what the new role does not need. This is the single commonest source of accumulated privilege.

The exit conversation

Ask, rather than only revoking

A short conversation at departure covering what the person holds, what is on any personal device, and what they should return, handled as routine housekeeping, recovers more than a technical process does and costs five minutes.

Most people answer honestly because most people are not doing anything wrong, which is the assumption the entry on what insider risk covers argues for throughout.

Also

Elsewhere in insider risk