Who can do what.
WHY IT MATTERS
Access determines what someone can take, change or destroy.
WHAT TO ESTABLISH
What each role needs, and grant only that.
WHY MINIMUM ACCESS
Excess access is exploited and it is rarely noticed.
WHAT TO MAINTAIN
A record of who has access to what.
WHAT TO REVIEW PERIODICALLY
Access against current roles.
WHY
Access accumulates as people change roles and it is never removed.
WHAT TO REMOVE IMMEDIATELY
Access for anyone who leaves.
WHY ON THE DAY
It is the standard failure, and it leaves exposure open indefinitely.
WHAT TO ESTABLISH
A leaver process covering every system, not just the obvious ones.
WHAT TO INCLUDE
Email and accounts Financial systems and banking Remote access Physical access and keys Shared credentials Accounts registered in their name
WHY ACCOUNTS REGISTERED IN THEIR NAME
Services registered to a departed person are lost or remain under their control.
WHAT TO AVOID
Shared accounts and shared passwords.
WHY
Actions cannot be attributed, and removal is impossible.
WHAT TO ESTABLISH
Individual accounts for everyone.
WHAT TO PROTECT MOST
Administrative access Banking access Access to customer and personal data
WHAT TO REQUIRE
Two-factor authentication on anything significant.
WHAT TO LOG
Access to sensitive systems and changes to key data.
WHY
It provides the record for any investigation.
WHAT TO ESTABLISH
That logs cannot be altered by those they record.