Provisioning

Creating an account and granting the access that an approved request or defined role specifies, at onboarding or on transfer; the lifecycle stage that deprovisioning later closes.

Provisioning is the step in the identity and access lifecycle that creates an account and grants it the access an approved request specifies. The ISC2 exam outline lists “Provisioning and deprovisioning (e.g., on/off boarding and transfers)” under objective 5.5. It happens at onboarding, when a person joins, and at transfer, when someone changes role. Access is commonly derived from the person’s defined role under role-based access control rather than copied from a colleague’s account. NIST SP 800-53 Rev. 5 AC-2 requires approval for requests to create accounts, and identity proofing comes first for a new identity.

Provisioning pairs with deprovisioning, and a transfer needs both: the new role’s access is added, and whatever the old role had that the new one does not need is removed. Skipping the second half is how privilege creep builds up. Federated services may create an account on first sign-in through just-in-time provisioning, and SCIM automates provisioning across applications. The asset sense, readying information, assets and systems for use, appears under outline objectives 2.3 and 7.3.

Exam relevance: a scenario is likely to describe a new hire given the same access as a predecessor, or a transferred employee who keeps old rights. Candidates are expected to tie provisioning to approval and role, and to treat a transfer as a deprovisioning event as well.