Over-provisioned standing access
Privilege creep
Also called: access creep
Privilege creep is the gradual build-up of access rights a person collects as they change jobs, join projects or cover for colleagues, without old rights being removed. Over time the account can reach far more than the current role needs, which widens the damage if the account is compromised or misused.
How it works
New access is requested and granted when someone moves or takes on work, but nobody owns removing the access they no longer need. Long-serving staff and administrators end up with standing privilege across many systems. An attacker who takes over such an account inherits all of it, and the excess can also create conflicting duties.
A real example
A September 2022 DHS Office of Inspector General audit found that USCIS did not have a process to adequately verify access after personnel transferred offices within the agency.
Source: USCIS Should Improve Controls to Restrict Unauthorized Access to Its Systems and Information (OIG-22-65) — US Department of Homeland Security, Office of Inspector General, 2022-09-07
How to stop it
Review access whenever someone changes role, remove rights tied to the old role by default, and run periodic certifications so managers confirm each person's current access. Replace standing privilege with time-limited grants.
Related terms
Sources
- USCIS Should Improve Controls to Restrict Unauthorized Access to Its Systems and Information (OIG-22-65) — US Department of Homeland Security, Office of Inspector General, 2022-09-07
Last reviewed Oct 2, 2026