by Heath Gieson

 

If access granting is where intent is established, access revoking is where discipline is revealed.

Most organizations do not struggle with revoking access because they disagree with the idea. They struggle because no one clearly owns the moment when access should end. Someone leaves the company. A role changes. A project wraps up. Everyone assumes the system will catch up on its own. It rarely does.

That gap is what Control 6.2 is meant to close.

Access does not quietly expire just because the business moves on. Without an intentional revocation process, access accumulates. Former employees retain credentials. Role changes stack new permissions on top of old ones. Temporary access becomes permanent by accident. None of this looks dramatic day to day, but over time it becomes one of the most reliable sources of preventable risk.

Earlier controls established why access should be granted deliberately. Control 6.2 exists to make sure that same deliberateness applies when circumstances change. Access that cannot be confidently removed was never truly controlled in the first place.

The most important decision in an access revoking process is not technical. It is ownership. Someone must be responsible for saying that access should end now. In well-functioning organizations, that responsibility sits with the business. Managers know when roles change. Project owners know when work is complete. Human resources knows when employment ends. Security defines the rules and ensures the process exists, but it should not be guessing when access is no longer justified.

This is why event‑driven revocation matters. Access should change because something happened, not because someone remembered. Termination, role change, project completion, and expiration of temporary access are all events the organization already understands. When those events occur, access should predictably follow. When revocation depends on memory or manual follow‑up, it eventually fails.

Fear is another quiet obstacle. Teams hesitate to remove access because they worry about breaking something. That hesitation is a signal that access was never well understood to begin with. A healthy revocation process includes confidence. Confidence that access can be removed deliberately and restored if necessary. That confidence comes from clarity and consistency, not from leaving access in place just in case.

Role‑based access makes revocation far easier to sustain. When access reflects what someone does, changing or removing access becomes a side effect of change, not a special operation. When access is built as a collection of individual permissions, revocation becomes slow, risky, and often avoided. Over time, that avoidance turns into accepted drift.

CIS IG1 does not require constant access recertification campaigns or complex tooling. For most organizations, effective revocation is tied to a small number of well understood triggers and executed consistently. If someone leaves the company and their access is not removed promptly, that is not a technology failure. It is a process failure.

From an audit perspective, Control 6.2 is about evidence of accountability. Can you show that access changes when people or roles change. Can you demonstrate that former employees no longer have access. Can you explain who is responsible for making that happen. When those answers are clear, audits become less about discovery and more about confirmation.

Operationally, revocation is where access control proves it is real. Granting access shows intent. Removing access shows discipline. Together, they determine whether identity is being actively managed or quietly accumulated over time.

Access will always change as the business changes. Control 6.2 ensures that access changes deliberately instead of lingering by default. When access can end cleanly, the organization gains confidence. When it cannot, the organization carries risk it no longer remembers choosing.

Access control is not defined by how easily access is granted. It is defined by how reliably access is removed when it no longer belongs.

Let's Connect. Make Better Technology Decisions with Forthright.

Understand your current environment and get a clear path forward. Let's connect.