Insider risk · 3.4
The fortnight around a departure
The fortnight around a departure. What the requirement says, what it means in practice, and what an assessor will ask.
For an adjacent operational perspective, fireable offenses explains the topic in a practical workplace context.
For an independent reference point, see CISA insider-threat mitigation resources.
The window
From resignation to the last day, and a while after
Research on data movement around departures consistently finds elevated activity in the weeks before somebody leaves. Most of it is ordinary: people gather their own work, examples of what they have done, contacts, things they consider theirs.
Some of it is not, and the two look similar in a log, which returns to the entry on what detection establishes.
The list
What has to happen on the last day
A written list, maintained, covering every system: accounts disabled, tokens revoked, physical access removed, devices collected, shared credentials the person knew changed, external services the company pays for reassigned.
The last two are the ones that fail. Shared credentials survive departures indefinitely, and the software account nobody knew about surfaces at renewal.
Before the conversation
For involuntary departures, plan first
Where an employment relationship is ending on the employer's initiative, the revocation should be prepared before the conversation and executed at an agreed moment.
This is ordinary practice, it is not an accusation, and it should be the same procedure for everybody so that applying it does not communicate suspicion about a particular person.
Notice periods
The awkward middle
Somebody who has resigned may work for weeks with full access. The options are to leave access unchanged, to reduce it to what the remaining work requires, or to end the working period early.
All three are legitimate and the middle one is usually right. Doing it as a stated policy applied to everybody avoids the situation where reducing one person's access is read as an allegation.
Proportion
Most leavers are not a problem
A departure process that treats every leaver as a suspect is unpleasant, damages the relationship with people who may return or refer others, and is disproportionate to what actually happens.
Consistency is what makes it acceptable: the same steps for everybody, explained as routine, applied to the chief executive as to the newest starter.
The review
Looking at recent activity, proportionately
A review of file activity in the notice period is reasonable where the role warranted access to controlled information. What it should produce is either nothing or a question, and the threshold for the question should be set before anybody looks.
Reviewing selectively, on suspicion, without a stated policy, is the arrangement most likely to go wrong in every direction at once.
Records
What to keep
The checklist, completed, with dates and the name of whoever did each item. Retained.
An assessor will ask how you know access was removed, and a completed checklist is the answer. An assurance that it is always done is not.
Transfers
The internal move nobody offboards
Somebody changes role and keeps the access from the old one. Repeated over several years this produces individuals with rights nobody would grant them today.
Apply the departure checklist to internal moves, removing what the new role does not need. This is the single commonest source of accumulated privilege.
The exit conversation
Ask, rather than only revoking
A short conversation at departure covering what the person holds, what is on any personal device, and what they should return, handled as routine housekeeping, recovers more than a technical process does and costs five minutes.
Most people answer honestly because most people are not doing anything wrong, which is the assumption the entry on what insider risk covers argues for throughout.
Also
Elsewhere in insider risk
- What the three levels are, and which appliesThe level is set by your contract, not by your size. Most suppliers handling controlled unclassified information are at the second.
- Reading the clause that binds youReading the clause that binds you. What the requirement says, what it means in practice, and what an assessor will ask.
- Which systems are in scopeWhich systems are in scope. What the requirement says, what it means in practice, and what an assessor will ask.
- Self-assessment, and why the scores driftedSelf-assessment, and why the scores drifted. What the requirement says, what it means in practice, and what an assessor will ask.
- Who assesses you, and how each kind worksWho assesses you, and how each kind works. What the requirement says, what it means in practice, and what an assessor will ask.
- What the standard does not requireWhat the standard does not require. What the requirement says, what it means in practice, and what an assessor will ask.
- Machines older than the requirementsA control written for a server, applied to a lathe with a shared login, a decade-old operating system and a USB port.
- Drawings, job packets and paperDrawings, job packets and paper. What the requirement says, what it means in practice, and what an assessor will ask.
- Removable media, and why bans failRemovable media, and why bans fail. What the requirement says, what it means in practice, and what an assessor will ask.
- Vendor remote accessVendor remote access. What the requirement says, what it means in practice, and what an assessor will ask.
- Technical data packages and what they containTechnical data packages and what they contain. What the requirement says, what it means in practice, and what an assessor will ask.
- Segmentation, and what it does not solveSegmentation, and what it does not solve. What the requirement says, what it means in practice, and what an assessor will ask.
- What insider risk actually coversWhat insider risk actually covers. What the requirement says, what it means in practice, and what an assessor will ask.
- What detection can and cannot establishWhat detection can and cannot establish. What the requirement says, what it means in practice, and what an assessor will ask.
- Monitoring, and where the law constrains itMonitoring, and where the law constrains it. What the requirement says, what it means in practice, and what an assessor will ask.
- Privileged access, and who reviews itPrivileged access, and who reviews it. What the requirement says, what it means in practice, and what an assessor will ask.
- False positives, and what they costFalse positives, and what they cost. What the requirement says, what it means in practice, and what an assessor will ask.
- The documents an assessor reads firstThe documents an assessor reads first. What the requirement says, what it means in practice, and what an assessor will ask.
- What counts as evidenceWhat counts as evidence. What the requirement says, what it means in practice, and what an assessor will ask.
- The findings that recurThe findings that recur. What the requirement says, what it means in practice, and what an assessor will ask.
- Plans of action, and their limitsPlans of action, and their limits. What the requirement says, what it means in practice, and what an assessor will ask.
- What the assessment week is likeWhat the assessment week is like. What the requirement says, what it means in practice, and what an assessor will ask.
- The certificate, and what it coversThe certificate, and what it covers. What the requirement says, what it means in practice, and what an assessor will ask.