TechKnowSurge
NIST CSF ID.AM-08 NIST 800-53 PM-9 ISC2 CC 1.2 NIST CSF GV.RM-01 NIST 800-53 PS-4 NIST 800-53 PS-5 NIST CSF GV.RR-04 NIST 800-53 AC-2
VideoSecurityFree

Protection - Cybersecurity Lifecycles

Cybersecurity risk management requires actively managing the full life cycle of people, processes, and technology — from initial deployment or onboarding through decommissioning or offboarding. Understanding these life cycles helps organizations reduce exposure and maintain consistent security controls.

Complete this video to capture a CTF flag worth 1 point.

About this video

Cybersecurity risk management is built around the concept of life cycles — the idea that people, processes, and technology each have a beginning, middle, and end that must be deliberately managed. Ignoring any phase of these life cycles creates gaps that can expose an organization to unnecessary risk, making a structured, consistent approach essential across all three domains. For personnel, the life cycle begins with onboarding, which should include cybersecurity awareness training as a standard component. As employees change roles within the organization, their access permissions must be updated to reflect their new responsibilities rather than accumulating privileges across departments. When an employee leaves, a formal offboarding process ensures accounts are decommissioned and system access is fully revoked. Processes governing these activities must themselves be treated as living documents — created with clear intent, implemented consistently, monitored for effectiveness, and revised when circumstances change. A process that never evolves becomes a liability rather than a safeguard. Technology follows the same pattern: systems are deployed, actively maintained throughout their operational life, and eventually retired through a controlled decommissioning process. That retirement phase carries its own security requirements, such as securely wiping storage media before disposal. Across all three areas, the key is to approach each life cycle as something that requires ongoing attention rather than a one-time setup.

What you'll learn

What's covered

Cybersecurity Life Cycles

Aligned to

NIST CSF
ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles.
GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders.
GV.RR-04 Cybersecurity is included in human resources practices.
NIST 800-53
PM-9 Risk Management Strategy
PS-4 Personnel Termination
PS-5 Personnel Transfer
AC-2 Account Management
ISC2 CC
1.2 Understand risk management concepts

Key terms

Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Identity and Access Management
IAM
A framework of policies and technologies that ensures the right users have appropriate access to resources.
Onboarding
The process of integrating a new employee into an organization, including provisioning system access, assigning permissions, and providing security awareness training.
Offboarding
The process of revoking a departing or transitioning employee's system access and decommissioning their accounts to prevent unauthorized access.
Personnel Lifecycle
The full span of an employee's relationship with an organization, encompassing onboarding, role transitions, and offboarding, each of which carries distinct cybersecurity implications.
Configuration Management
The process of tracking and controlling changes to hardware, software, and documentation throughout a system's lifecycle.
Access Control
A security mechanism that restricts access to resources based on policies, roles, or identity.

Topics

Cybersecurity Risk Management Security Lifecycle Personnel Security Onboarding Offboarding Access Control Identity Management

Transcript

One of the terms you'll hear in this industry is a life cycle. It's just the idea that something has a beginning, middle and end to it. When it comes to cybersecurity, we need to think about the beginning, middle and end to our different technologies and the different areas of cybersecurity. So let's get into some life cycles that you'll need to manage from a risk perspective.

When it comes to life cycles, we're really talking about the people, process and technology. Each one of these has a beginning, a middle and an end.

People

When it comes to people, you are going to hire somebody, and there's an onboarding process, and hopefully part of that onboarding process is training, and hopefully part of that training is cybersecurity awareness training. So there is an onboarding process that you go through with each of your employees to bring them on board.

And then once they're on board, things are usually not stagnant and stay the same. Usually within the company people are moving around, and so you need to be thinking about what's going to happen when people move around. You don't want them moving from department to department and position to position and gathering up more and more access to all of your systems. Instead, what you want to do is when they move from one department to another, you need to offboard them from one department and onboard them onto another department and make sure the permissions change with that.

And then when they leave the company, then there's an offboarding process to decommission those accounts and take them out of the systems. So these all need to be well defined.

Process

That comes to a certain degree into your processes. As you create your process: what are your onboarding processes, what are your offboarding processes? Make sure they're well defined and followed consistently.

So you're going to create those processes, you're going to implement those processes, you'll monitor them to make sure that they continue to operate as desired, and when there are problems then you would adjust those problems to meet the new needs. So you're constantly changing those. It's something that's going to be dynamic. Your processes should be dynamic and shouldn't be so stagnant where they're never changing.

Technology

And then same thing with your technology. I've got a typewriter here. Technology goes bad after a while, so you're going to have to deploy new technology. Once it's up and running, you're going to have to maintain that, and then when it's ready to get rid of, you're going to have to decommission it. You wouldn't want to decommission your servers without wiping those drives first, so that's an example of the decommission process.

So we just need to think about these life cycles, and we're going to manage those life cycles in each one of these areas.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →