Physical access privileges are revoked when no longer needed, at least in an ad hoc manner
Asset owners and custodians are responsible for revoking physical access privileges when they are no longer required by whoever (or whatever) they were assigned to, such as upon an employee's termination or transition to a new role. Generally, staff should maintain the minimum set of privileges needed to perform their assigned responsibilities. Revoking physical access that is no longer required helps prevent aggregation of access privileges.
Related Practices · Input From: Implementing ARCHITECTURE-3a provides input that may be useful for implementing this practice. · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ACCESS-3b, ACCESS-3h, ACCESS-3i.