Knowing who has access.
WHAT TO INVENTORY
Every system and service in use Every account on each Who each account belongs to What each account can do
WHY EVERY SERVICE
Access exists in places nobody maintains a list of.
WHAT IS COMMONLY MISSED
Services subscribed to by individuals Systems set up for a project and forgotten Accounts on suppliers' and partners' systems Administrative accounts on equipment Accounts used by software rather than people
WHY SERVICE ACCOUNTS DESERVE ATTENTION
They frequently hold broad permissions, never expire, and belong to nobody.
WHAT TO ESTABLISH FOR EACH
What it is used for What depends on it Who is responsible for it
WHAT TO IDENTIFY
Accounts nobody can explain.
WHAT TO DO ABOUT THEM
Establish their purpose or disable them.
WHY DISABLE RATHER THAN DELETE INITIALLY
It is reversible if something breaks.
WHAT TO ESTABLISH ABOUT EACH SERVICE
Which business account owns it Who the administrators are How access is granted and removed
WHY THE OWNING ACCOUNT
Services registered to an individual's address are lost when they leave.
WHAT TO VERIFY
That every business service is registered to an address the business controls.
WHAT TO MAINTAIN
The inventory, updated as services are added.
WHAT TO ESTABLISH
That new services are recorded when adopted.
WHY
Undocumented services are where forgotten access persists.
WHAT TO REVIEW
The inventory, periodically and when anyone leaves.