Skip to main content

CCC.IAM.C07: Automate Identity De-provisioning

Control ID:CCC.IAM.C07
Title:Automate Identity De-provisioning
Objective:Ensure that when an identity is terminated in the central Identity Provider (IdP), ts corresponding access to cloud resources is revoked automatically.
Control Family:
Identity Provisioning and Lifecycle

Related Threats

IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.IAM.TH10Orphaned Federated Identity Retains AccessA federated identity is de-provisioned from the external Identity Provider (IdP), but its corresponding cloud identity remains active within the cloud environment. This orphaned identity creates a latent access path that could be exploited if the original username is reactivated or reassigned in the IdP, granting unintended access to a new principal.
1
1
0
CCC.IAM.TH01Valid Cloud Credentials AbuseValid identity credentials such as access keys, tokens or passwords are misused or compromised. Examples include public exposure, token theft, unprotected metadata service of a compromised compute instance or brute-force attacks. The use of these credentials can provide unauthorized access to the cloud environment, potentially bypassing other security controls and enabling lateral movement across cloud resources.
1
1
0

Related Capabilities

IDTitleDescription
CCC.IAM.F08Federated Identity - SAMLSupport for user authentication outside the cloud service provider using SAML. Authenticated federated identities can assume IAM roles.
CCC.IAM.F09Federated Identity - OIDCSupport for user authentication outside the cloud service provider using OIDC. Authenticated federated identities can assume IAM roles.

Guideline Mappings

Reference IDEntry IDStrengthRemarks
NIST-CSF
PR.AA-01
0
-
NIST_800_53
AC-2
0
-

Assessment Requirements

IDDescriptionApplicability
CCC.IAM.C07.TR01When a user account is disabled or deleted in the organization's IdP, the corresponding cloud identity and its access policies MUST be disabled or deleted within 24 hours.
tlp-clear
tlp-green
tlp-amber
tlp-red