Annex 11.5.1
Mapped SPARTA techniques (6)
Techniques referencing this article
Identity life-cycle management ensures the population of legitimate identities is constrained and current, narrowing the surface for masquerading as an authorized actor.
Identity life-cycle management bounds the population of valid credentials and ensures stale or compromised identities are revoked promptly, narrowing the surface for credentialed evasion.
Identity life-cycle management governs how cryptographic keys, including uplink-MAC and link-encryption keys, are issued, rotated and revoked; the implementing regulation's identity-life-cycle obligation is the procedural envelope around the keys this technique rotates under attacker control.
Identity life-cycle management of service accounts, user accounts and maintenance access is the procedural mechanism that bounds the dwell time of credentialed persistence; revoked, rotated or expired credentials cannot underpin long-lived access.
Identity life-cycle management governs how cryptographic identities (uplink-MAC keys, link-encryption keys, certificate-bound operator identities) are issued, rotated and revoked; weak life-cycle is the precondition for adversary key acquisition.
Identity life-cycle management is the precise control the implementing regulation requires the entity to apply to operator identities, service accounts and tokens — the targets of credential reconnaissance.