Identity Governance

Identity governance is the set of policies, processes, and technologies that ensures the right individuals have the right access to the right resources at the right time, and that every one of those access rights can be justified and reviewed. It sits above day-to-day authentication and focuses on oversight of who has access and why.

In practice it covers joiner, mover, and leaver workflows, access certification campaigns where managers periodically re-approve entitlements, segregation of duties enforcement, and reporting for auditors. Consider an employee who changes roles three times in five years: without governance, old permissions accumulate into privilege creep, and that stale access is exactly what attackers and auditors both find. The discipline people underestimate is regular access review, since provisioning an account is easy but proving months later that its access is still appropriate is the hard, valuable part. Governance tools automate these reviews and produce the evidence compliance frameworks demand.

Why does identity governance matter for the CISSP exam?

It belongs to Domain 5, Identity and Access Management. Candidates should understand the identity lifecycle, access reviews and certification, segregation of duties, and how governance differs from the mechanics of authentication.