C.12 Identity Management Policy

Version: April 2025
Applies to: All employees, contractors, and stakeholders
Aligned with: ISO/IEC 27001:2022 (A.5.16–A.5.20, A.8.2), NIST SP 800-63

Purpose
To ensure user identities are securely created, managed, and terminated — with proper authentication and access controls — reducing the risk of unauthorized access and insider threats.

1. Scope
Covers:
- Account provisioning, modification, and deactivation
- Identity providers (IdPs), password and authentication policies
- Human Resources onboarding/offboarding procedures
- Multi-factor authentication (MFA) and behavioral analytics

2. Core Identity Requirements

ID Requirement
ID-01 Maintain a formal HR program to manage personnel identities
ID-02 Use an HRIS to track employee status
ID-03 Conduct background screening on all workforce members
ID-04–07 Require formal acceptance of terms and return of assets, data, and credentials upon offboarding
ID-08 Maintain an inventory of approved Identity Providers (IdPs)
ID-09 Minimize number of IdPs; use centralized SSO where possible
ID-10–11 Track all user accounts & maintain secure IdP configurations
ID-12–14 Prevent account sharing, reuse, and concurrent logins
ID-15 Perform regular identity reviews to ensure account validity
ID-16–17 Automate provisioning/de-provisioning via HRIS integration
ID-18–24 Enforce secure authentication policies:
• Strong passwords
• Lockouts on failed attempts
• Password hashing/salting
• MFA required
• Encrypted transmission
• Secure helpdesk reset process
• Disable stale/inactive accounts
ID-25–27 Log all:
• Logon attempts
• Access to deactivated accounts
• User Behavior Analytics (UBA) events

3. Enforcement & Sanctions
Non-compliance may result in:
- Mandatory training or written warnings
- Access suspension or termination
- Legal action in case of violations of law or contractual duties

Enforcement is handled fairly and in accordance with HR and security governance.

Direct URL: