Means
Aiding and Abetting
Asset Control
Bluetooth
Bring Your Own Device (BYOD)
Clipboard
FTP Servers
Installed Software
Media Capture
Network Attached Storage
Physical Disk Access
Printing
Privileged Access
Removable Media
Screenshots
SMB File Sharing
SSH Servers
System Startup Firmware Access
Unrestricted Software Installation
Unrevoked Access
Web Access
- ID: ME021
- Created: 19th June 2024
- Updated: 19th June 2024
- Contributor: The ITM Team
Unrevoked Access
The subject has left the organization but still has access to services or data that is reserved for employees.
Subsections
ID | Name | Description |
---|---|---|
ME021.004 | API Keys | API keys that were available to the subject during employment are not revoked and can still be used. |
ME021.006 | Multi-Factor Authentication | MFA tokens or hardware devices (such as physical security keys) issued to the subject during employment are not deactivated and can still be utilized. |
ME021.003 | Physical Access Credentials | Physical security credentials, such as an ID card or physical keys, that were available to the subject during employment are not revoked and can still be used. |
ME021.005 | SSH Keys | SSH keys that were available to the subject during employment are not revoked and can still be used. |
ME021.001 | User Account Credentials | User credentials that were available to the subject during employment are not revoked and can still be used. |
ME021.002 | Web Service Credentials | Web credentials that were available to the subject during employment are not revoked and can still be used. |
Prevention
ID | Name | Description |
---|---|---|
PV023 | Access Reviews | Routine reviews of user accounts and their associated privileges and permissions should be conducted to identify overly-permissive accounts, or accounts that are no longer required to be active. |
PV024 | Employee Off-boarding Process | When an employee leaves the organization, a formal process should be followed to ensure all equipment is returned, and any associated accounts or access is revoked. |