- HR notifies IT within [2] hours of the departure decision
- Accounts disabled, not deleted; password reset; active sessions revoked
- Mailbox frozen; forwarding set per policy; nobody logs in as the user
- Removed from all groups; group export saved as evidence
- Card access revoked; badge and keys collected
- Laptop, phone, tokens returned; devices wiped or reimaged
- Personal-device access removed: mail, VPN, cloud
- Clearance sponsor notified where the contract requires it
- Checklist signed by IT and HR; filed with the date
Free to use, edit, and share, including by an MSP for a client, under CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with it. None of it is legal advice or a substitute for the contract clauses in front of you.
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.