A.5.16 Identity Management
1. Unified Identity Lifecycle Strategy
anDREa manages the full lifecycle of digital identities—encompassing internal employees, external contractors, and myDRE platform users—from initial provisioning to final deactivation. This comprehensive framework satisfies ISO/IEC 27001 Annex A.5.16 and aligns with NIS 2 Directive identity assurance standards.
By enforcing Role-Based Access Control (RBAC) and the Principle of Least Privilege (PoLP), anDREa ensures that every identity corresponds to a verified business need and is protected by strong authentication boundaries.
2. Identity Lifecycle Phases
2.1 Identity Creation (Provisioning)
- Onboarding Integration: Formal onboarding procedures dictate the instantiation of new digital identities. Access rights are determined solely by job roles and restricted to the minimum required resources.
- Verification Gate: Identity parameters and official documents are validated at onboarding and re-verified whenever a new corporate ID token is issued.
- Authentication Baseline: Multi-factor authentication (MFA) is strictly enforced upon creation across all platforms. Where technically supported by the infrastructure, passwordless authentication architectures are deployed to replace traditional MFA.
2.2 Access Management & Just-in-Time Elevation
- Central Registry: All active identity permissions and profile assignments are recorded and tracked inside the andREa's HR Hub.
- Just-In-Time (JIT) Elevation: Standing administrative privileges are prohibited. Elevated permissions within our cloud fabrics require explicit activation through temporary JIT mechanisms (such as Azure Privileged Identity Management), reducing the threat surface of persistent access.
- Workflow Automation: Access requests and approval escalations follow structured, automated workflows that produce immutable, auditable log records.
2.3 Continuous Governance & Maintenance During Engagement
- Role Modifications: Internal cross-departmental transfers, status changes, or adjustments to operational responsibilities trigger an immediate, corresponding modification of identity permissions.
- Automated Identity Scans: To prevent account sprawl and detect invalid configurations, an automated script executes on a weekly cadence to isolate and flag corporate identity accounts whose associated credentials or IDs are set to expire within a predefined number of months.
- Platform Access Reviews: Workspaces within the myDRE platform undergo scheduled and ad-hoc Access Review Policy. These automated check-loops isolate, flag, and facilitate the removal of inactive, orphaned, or excessive accounts within active research environments.
- Anomaly Detection: Identity authentication telemetry is audited continuously to isolate threat indicators, including unauthorized access attempts, concurrent geographic logins, or the utilization of expired tokens.
2.4 Privileged Identity Management (PIM)
- Privileged Identity Hardening: All identities holding administrative, systemic, or infrastructure-wide scope are subject to advanced multi-factor challenge rules and managed under strict credential-vaulting parameters.
- Duties Separation & Monitoring: Segregation of duties is enforced at the identity layer to prevent toxic permission combinations (A.05.03 - Segregation of duties). High-privilege identity telemetry is logged non-repudiably to ensure rapid detection and response to potential profile abuse.
2.5 Identity Deactivation (De-provisioning)
Upon termination of employment, contract completion, or partnership expiration, anDREa triggers an immediate, synchronized de-provisioning sequence.
- Checklist Execution: HR and security managers execute localized decommissioning paths driven by Onboarding & Offboarding Process.
- Infrastructure Revocation: Operational access across cloud services, internal code repositories, and third-party SaaS applications is terminated immediately using explicit infrastructure guidelines:
- Microsoft Azure: Execution of the Emergency Brake Instructions playbook to immediately disable Entra ID access profiles.
- Google Workspace: Execution of the Suspend a User administrative protocol to freeze corporate communication and document shares.
- Resource Recovery & Offboarding Archival: Subscriptions, licenses, enterprise files, and business email caches are securely reassigned or recovered by management according to corporate data retention periods.
- Audit Proof: Verifiable evidence of successful identity de-provisioning is compiled within a finalized DocuSign Offboarding Document and attached permanently to the individual's restricted personnel dossier.
3. Training and Awareness
To safeguard the identity perimeter against social engineering and credential stuffing:
- User Training: All personnel receive mandatory onboarding and annual security awareness training highlighting credential hygiene, phishing recognition, and secure access procedures.
- Administrative Training: Systems engineers, identity managers, and Google/Azure administrators receive specialized technical training regarding secure lifecycle management, PIM administration, and compliance logging rules.