I recently had a task: Find an industry best practice that says you need to remove all rights or permissions or groups from the account of a former employee, rather than just disabling the account.
There was only one problem. I could find no such thing. None. Nothing. In fact, I expect this blog entry to rocket to the top of the Google search results for just such a thing, because no such guidance exists. The question is, will anyone else ever search for such a thing. Read more

David Farquhar is a computer security professional, entrepreneur, and author. He has written professionally about computers since 1991, so he was writing about retro computers when they were still new. He has been working in IT professionally since 1994 and has specialized in vulnerability management since 2013. He holds Security+ and CISSP certifications. Today he blogs five times a week, mostly about retro computers and retro gaming covering the time period from 1975 to 2000.
