Privilege creep

Access that piles up over time when a person moves between roles or projects and gains new rights without losing the old, until they hold more than their current job requires.

Privilege creep, also called access creep, is the slow widening of a person’s access beyond what their current role needs. It commonly follows transfers, promotions, temporary projects and cover arrangements: each change adds rights, and nothing removes the rights that belonged to the role left behind. It sits under objective 5.5 of the ISC2 exam outline, which lists role definition and transition, and provisioning and deprovisioning including transfers.

Creep breaks least privilege and can quietly defeat separation of duties when one person ends up holding two duties that were deliberately split. The preventive point is the transfer itself: provisioning the new role’s access and deprovisioning whatever the old role had that the new one does not need. Defining roles from job duties under role-based access control helps; copying another user’s entitlements does not, because it copies any creep they carry as well. A periodic access review finds creep after the fact, so it detects rather than prevents.

Exam relevance: a scenario is likely to describe a long-serving employee who has worked in several departments and still holds access from each. Candidates are expected to name privilege creep, to see the transfer process as the preventive control, and to see the access review as the detective one.