Provisioning and Deprovisioning Policy

Version 2.0

For Students, Faculty, Staff, Guests, Alumni

Purpose

The purpose of this policy is to establish requirements for the issuance, modification, review, suspension, and revocation of access to University IT Resources for person and non-person entities affiliated with the University.

Scope

This IT security policy, and all policies referenced herein, shall apply to all members of the University community, including faculty, students, administrators, staff, alumni, authorized guests, delegates, and independent contractors (the “User(s)” or “you”) who use, access, or otherwise employ, locally or remotely, the University’s IT Resources, whether individually controlled, shared, stand-alone, or networked.

Policy Statement

  • Access to University IT Resources must be granted only to authorized persons and non-person entities based on a valid University business, academic, or operational need and the Principle of Least Privilege.
  • Access privileges must reflect assigned responsibilities and authorized security or privacy level.
  • Provisioning or deprovisioning must follow a documented account-management process that addresses request, approval, creation or activation, modification, periodic review, suspension or disabling, and removal.
    • Requests to create or materially change access must be approved by an appropriate supervisor, sponsor, system owner, or other authorized University representative before access is granted.
  • Fordham username (i.e., individual default) accounts must be limited to approved uses based on role.
    • Access rights and account status must be reviewed periodically and when an individual’s role, affiliation, business need, or authorized access changes.
    • Access that is no longer required or appropriate must be removed or modified promptly.
  • Designated accounts such as Corporate, Generic, service, administrative, and other non-person accounts must be formally authorized, limited to approved uses, assigned to a responsible owner, and reviewed.
  • Credentials must be changed when a User with knowledge of those credentials no longer requires access, or when compromise is suspected.
  • Responsibilities for requesting, approving, provisioning, and reviewing access must be separated where practical to reduce conflicts of interest and unauthorized privilege changes.
  • When an individual’s role or affiliation is modified or terminated, or access is no longer required, it is the responsibility of the managing supervisor (or higher) to notify Human Resources and the IT Service Desk, as applicable, before the effective status change.
  • Required access changes must be completed by the effective date and time of the change.
  • Upon termination or separation, applicable system access must be disabled or removed, associated authenticators and credentials must be revoked as appropriate, and University system-related property and access media must be returned in accordance with applicable University procedures.
  • All provisioning and deprovisioning requests and resulting account lifecycle actions must be recorded in ServiceNow or another University-approved system of record to support review, auditing, and compliance.
  • Access to University IT Resources is subject to monitoring and logging in accordance with applicable University policies.
  • IT Resources that do not use centrally managed services (e.g., Central Authentication Service) or do not have an automatic provisioning/deprovisioning process in place must be manually provisioned or deprovisioned by the responsible individual(s) by the effective date and time of the change (e.g., termination, separation, or role change).
  • Non-centrally managed accounts include but are not limited to:
    • Service accounts,
    • Administrative accounts,
    • Educational Technologies and Research Computing accounts,
    • Database accounts,
    • Application-based accounts, or
    • Corporate and Generic Accounts. 

Definitions

Corporate Accounts are departmental or group email accounts.

Deprovisioning is the term used when account access is suspended or disabled from use.

Fordham username is an identifier used to access University systems. A username may have multiple role-based email accounts associated with it; access to services depends on role. 

Generic Accounts are considered accounts not derived using the faculty, staff, or student naming convention. There is no corresponding ID associated with a Generic Account. These accounts do not identify the person or entity using the account. See the Generic Account Policy.

IT Resources include computing, networking, communications, application, telecommunications systems, infrastructure, hardware, software, data, databases, personnel, procedures, physical facilities, cloud-based vendors, Software as a Service (SaaS) vendors, and any related materials and services.

Principle of Least Privilege is the cybersecurity practice that individuals should have access to only IT Resources and functions required to perform their stated duties.

Provisioning is the term used to create or provide specific accounts and applicable access.

Related Policies and Procedures

NIST SP 800-53 Rev. 5 Alignment

  • Access Control: AC-2 Account Management; AC-5 Separation of Duties; AC-7 Unsuccessful Logon Attempts; AC-11 Session Lock; AC-12 Session Termination; AC-16 Security and Privacy Attributes.
  • Personnel Security: PS-2 Position Risk Designation; PS-8 Personnel Sanctions.

Implementation Information

Review Frequency Annual
Responsible Person Senior Director of IT Security and Assurance 
Approved By CISO
Approval Date March 1, 2017

Revision History

Version Date Description
1.0 03/01/2017 Initial document
1.0.1 03/07/2018 Grammatical changes only. No adjustments to the policy
1.0.2 06/25/2018 Updated disclaimers, scope, and definitions
1.0.3 09/30/2019 Updated definitions
1.0.4 11/11/2019 Updated policy statement
1.1 12/04/2020 Updated the purpose and policy statements
1.2 11/09/2021 Updated policy statement
1.3 11/11/2022 Updated definitions, links, and Sr Director title
1.4  03/30/2023 Updated policy statement and definitions 
1.5 04/30/2024 Updated policy statement, scope, and disclaimer
1.6 05/16/2025 Updated policy statement and scope 
2.0 08/25/2026 Incorporated NIST SP 800-53 Rev. 5 controls AC-2, AC-5, AC-7, AC-11, AC-12, AC-16, PS-2, and PS-8 into the policy statement.

Policy Disclaimer Statement

Deviations from policies, procedures, or guidelines published and approved by Information Security and Assurance (ISA) will only be considered cooperatively between ISA and the requesting entity with sufficient notice to allow for conducting appropriate risk analysis, documentation, review, and notification to authorized University representatives where necessary. Failure to adhere to ISA written policies may be met with University sanctions up to and including dismissal.

Need Help?


Walk-In Centers

McShane Center 266 | RH
Leon Lowenstein SL18 | LC

View Our Walk-In Hours