Knowledgebase

Controlling System and Data Access Print

  • 0

Who can do what.

WHY IT MATTERS

Access determines what someone can take, change or destroy.

WHAT TO ESTABLISH

What each role needs, and grant only that.

WHY MINIMUM ACCESS

Excess access is exploited and it is rarely noticed.

WHAT TO MAINTAIN

A record of who has access to what.

WHAT TO REVIEW PERIODICALLY

Access against current roles.

WHY

Access accumulates as people change roles and it is never removed.

WHAT TO REMOVE IMMEDIATELY

Access for anyone who leaves.

WHY ON THE DAY

It is the standard failure, and it leaves exposure open indefinitely.

WHAT TO ESTABLISH

A leaver process covering every system, not just the obvious ones.

WHAT TO INCLUDE

Email and accounts Financial systems and banking Remote access Physical access and keys Shared credentials Accounts registered in their name

WHY ACCOUNTS REGISTERED IN THEIR NAME

Services registered to a departed person are lost or remain under their control.

WHAT TO AVOID

Shared accounts and shared passwords.

WHY

Actions cannot be attributed, and removal is impossible.

WHAT TO ESTABLISH

Individual accounts for everyone.

WHAT TO PROTECT MOST

Administrative access Banking access Access to customer and personal data

WHAT TO REQUIRE

Two-factor authentication on anything significant.

WHAT TO LOG

Access to sensitive systems and changes to key data.

WHY

It provides the record for any investigation.

WHAT TO ESTABLISH

That logs cannot be altered by those they record.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot