Provisioning
Provisioning is the process of creating and setting up the accounts, access rights, and IT resources that a user or system needs to do its work. In an access-management context, it typically means giving a new employee or service an identity in a target system along with the appropriate permissions. The reverse process, de-provisioning, removes that access when it is no longer needed.
Provisioning is the process of creating an identity and associated entitlements in one or more target systems, generally spanning the network, server, application, and user levels, based on defined conditions or policy. In IAM contexts it covers the lifecycle steps of establishing accounts, assigning access rights, and configuring the resources a user or system requires, and it is paired with de-provisioning to revoke identities and access when they are no longer authorized. In compliance engagements, provisioning and de-provisioning controls are commonly examined as evidence of logical access management; however, the specific controls assessed, their required attributes, and their treatment depend on the auditor, certification body, scope, and applicable criteria, and are not defined by the sources here as part of any particular framework requirement.
Why it matters
Provisioning sits at the center of logical access management because it determines who, or what, can reach a given system and with what permissions. When provisioning is well governed, access aligns with a user's role and responsibilities; when it is not, accounts can accumulate excess entitlements, orphaned accounts can persist after a person leaves, and unauthorized access can go undetected. De-provisioning is the equally important counterpart: revoking identities and access when they are no longer authorized prevents former employees, contractors, or decommissioned services from retaining a foothold in the environment.
In SOC 2 examinations and ISO 27001 certification engagements, provisioning and de-provisioning controls are commonly examined as evidence that access is granted and removed in a controlled, authorized manner. That said, the specific controls assessed, the attributes an auditor or certification body expects to see, and how they are treated depend on the engagement scope, the applicable criteria, and the practitioner performing the work. The sources here do not define provisioning as a named requirement of any particular framework, and demonstrating a sound provisioning process for one framework does not automatically satisfy the requirements of another.
Because provisioning spans the network, server, application, and user levels, gaps in one layer can undermine controls in another. Treating provisioning as a lifecycle discipline, rather than a one-time setup task, helps organizations keep access commensurate with need over time and produce the kind of evidence auditors and certification bodies typically look for.
Who it's relevant to
Inside Provisioning
Common questions
Answers to the questions practitioners most commonly ask about Provisioning.