Provisioning, deprovisioning and access reviews
Running the people side of an access control system: access levels and schedules built on least privilege, approvals from area owners, joiners, movers and leavers, lost credentials, temporary and contractor access, keys and combinations, and periodic access reviews and log audits, using NIST SP 800-53 PE-2, PE-3, PE-6, PS-4 and PS-5 as a reference model.
- Level
- Intermediate
- Length
- About 55 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 3 Oct 2026
Skills you'll practise
- Design access levels that give each role only the doors and times it needs
- Process joiner, mover and leaver changes with the right approvals and confirm they reached every controller
- Handle lost credentials, temporary access and keys or combinations so no uncontrolled access remains
- Run an access review with area owners and record the outcome
- Reconcile active credentials against an HR list and find access that should have been removed
Course outline
- 1.Provisioning, deprovisioning and access reviewsVideo · 2 min
- 2.Access levels and approvalsLesson · 16 min
- 3.Joiners, movers, leavers and lost credentialsLesson · 20 min
- 4.Access reviews and auditsLesson · 18 min
- 5.Provisioning, deprovisioning and access reviews: knowledge checkKnowledge check · 18 questions
- 6.A contractor who left last month opened the plant roomScenario
- 7.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- NIST SP 800-53 Rev. 5: PE-2 Physical access authorizations, PE-3 Physical access control, PE-6 Monitoring physical access, PE-8 Visitor access records, PS-4 Personnel termination, PS-5 Personnel transfer
- CISA: Insider threat mitigation (an insider is anyone who has or had authorized access; combine physical security, personnel awareness and information-centric measures)
- NIST SP 800-116 Rev. 1: Guidelines for the Use of PIV Credentials in Facility Access (threats: identifier collisions, revoked cards, skimming, sniffing, cloning; Controlled / Limited / Exclusion areas and 1 / 2 / 3 authentication factors; US federal guidance used here as an example)
- General access control installation and administration practice (starter content; needs subject review)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.