Philippines staffing research ·
Do expiry checks reduce lingering privileged access?, September 11 protocol
A cohort audit of time-bound requests, provisioning evidence, and verified removal states.
Key Stats
NIST SP 800-53 Rev. 5 includes access-control and account-management controls, but it does not set one universal privileged-access duration for every organization.
Methodology
Scope: a prospective twelve-week cohort study of eligible time-bound privileged-access requests for selected systems. Compare request packets and verified account states before and after an expiry-check routine, stratified by system and privilege class. A security reviewer independently verifies a 20% sample. No credentials, client accounts, production systems, or access changes were used in preparing this protocol.
Key Takeaways
The unit is a granted role on a named system, not the ticket. Define approved privilege classes, start and expiry events, verification methods, and service-account exclusions before observation.
Measure packets with complete approval evidence, grants matching approved scope, accounts verified at expiry, removals verified, extensions approved before expiry, and unresolved discrepancies. A closed ticket is not evidence that access changed.
Philippines-based helpdesk staff may validate packet fields, route approvals, schedule checks, and collect permitted system evidence. Security and system owners retain approval, provisioning authority, risk acceptance, investigation, and emergency-access decisions.
Inference boundary and limitations: The design is observational. Selection effects, changes in case mix, missing records, reviewer learning, policy changes, seasonality, and work completed outside the tracked system can explain an observed difference. Results do not establish causation, worker quality, compliance, or business impact.
The result applies only to sampled systems, role types, verification methods, and the twelve-week cohort. Fewer lingering grants would not prove that permissions were least privilege, accounts were never misused, or the organization was secure.
Observation record
Capture requester, system, role, purpose, approval evidence, grant state, start, planned expiry, extension, observed expiry state, removal evidence, reviewer, and cutoff.
Analysis plan
Use cohort counts and time-to-verified-removal distributions by system and role. Keep unobservable states distinct from confirmed lingering access.
Next step
Select one system, define accepted state evidence, and review a time-bound cohort with its security owner.
FAQs
Can ticket closure stand in for access removal?
No. The study requires evidence from the approved system or another verification method accepted by the security owner.
Does this study assess whether an access grant was necessary?
Only to the extent that required approval evidence is present. The authorized approver owns the necessity and risk judgment.
Sources
- https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
- https://www.cisa.gov/resources-tools/resources/guidance-best-practices-event-logging-and-threat-detection
- https://www.gao.gov/products/gao-20-283g