Inadequate Identity Governance
Overview
Inadequate identity governance refers to insufficient controls and processes for managing user identities, access rights, and privileges within an organization. This weakness arises when organizations fail to enforce proper identity lifecycle management, role-based access controls, and regular access reviews.
Why It Matters
- Security impact: Increases the risk of unauthorized access, privilege escalation, and insider threats.
- Business risk: Can lead to data breaches, regulatory non-compliance, and reputational damage.
- Common consequences: Unauthorized data exposure, fraud, operational disruption, and financial loss.
Where It Appears
- Environments: Enterprise IT infrastructures, cloud environments, and hybrid systems.
- Systems or processes: Identity and access management systems, user provisioning workflows, and access review procedures.
- Typical conditions: Lack of automated access controls, infrequent access audits, and poorly defined user roles.
How It Is Exploited (High Level)
Attackers exploit inadequate identity governance by obtaining or abusing excessive or outdated access rights, enabling them to move laterally within networks, access sensitive data, or perform unauthorized actions without detection.
How It Is Addressed (High Level)
Effective identity governance is achieved through implementing strong access control policies, enforcing least privilege principles, conducting regular access reviews and certifications, and automating identity lifecycle management processes.
Related Topics
Access control, identity and access management (IAM), least privilege, privilege escalation, insider threat, role-based access control (RBAC), identity lifecycle management.