Simulated workplaceCAQA Nova Digital Systems is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
ICTCAQA NovaSimulated workplace
Back to library
CAQA Nova Digital Systems · Simulated workplace

User Onboarding, Offboarding and Access Procedure

ProcedureControlled document
NOV-PRO-011
v2.5
Document ownerCyber Security Lead
Version2.5
Approved2 March 2026
Next review2 March 2027
StatusCurrent

Purpose. This procedure controls how user accounts and access are created, changed and removed for client and Nova users.

1.Scope

This procedure applies to all accounts on client identity platforms, line of business applications and Nova internal systems. It applies to service desk analysts, engineers and Business Services.

2.Authorised requesters

Account requests must come from a person listed as an authorised requester on the client's record. Requests from anyone else must be confirmed with an authorised requester before action. Requests must be logged as a ticket and must state the role, start date, required group memberships and any application access.

3.Onboarding

New accounts will be created from the client's role template so that group memberships are consistent. Multi-factor authentication must be enrolled before the account is handed over. Temporary passwords must be delivered by a separate channel from the username and must be changed at first sign in. The ticket must record the account name, groups and licence assigned.

  • Role template applied
  • Multi-factor authentication enrolled
  • Password delivered separately
  • Licence and groups recorded in the ticket

4.Changes to access

Requests for additional access must state the business reason and be approved by the authorised requester. Administrative privileges must be approved by the Cyber Security Lead and reviewed quarterly.

5.Offboarding

On notice of a departure the account must be disabled at the agreed time on the last day, sessions revoked, multi-factor tokens removed, mailbox and files delegated to the manager and the device recovered. Accounts will be deleted 90 days after disabling unless the client requests retention in writing. Urgent departures must be actioned within one hour of the request.

6.Access reviews

Each quarter the client's authorised requester will be sent a list of active accounts and privileged users for confirmation. Accounts not confirmed within 14 days will be disabled and the review recorded.

NOV-PRO-011 v2.5 · CAQA Nova Digital SystemsUncontrolled when printed. Simulated document created by CAQA for training and assessment.