Identities (users) are created, and access to assets is provisioned, before confirming if the identity (user) has a genuine need for access
Context and Guidance: Identities (users) are the means used to enable access to assets (such as networks, systems, and applications).
It is important that access provisioning follows the principle of least privilege. This means it is important that: (a) identities (users) are only created for individuals with a genuine business need for access, and; (b) access is only provisioned to identities (users) after the requirement for the level of access has been established.