Deciding what people need.
WHAT THE PRINCIPLE IS
Access limited to what the role requires.
WHY
It limits what a compromised account or a dishonest person can reach.
WHAT TO ESTABLISH FOR EACH ROLE
What systems they need What they need to do in each Whether they need to read, change or administer
WHY THE DISTINCTION
Most people need to read far more than they need to change.
WHAT TO GRANT BY DEFAULT
The minimum.
WHAT TO ADD
What is requested and justified.
WHY REQUESTED RATHER THAN ANTICIPATED
Anticipated access is never removed if it turns out to be unnecessary.
WHAT TO ESTABLISH ABOUT ADMINISTRATIVE ACCESS
Who genuinely requires it That it is separate from ordinary accounts
WHY SEPARATE ACCOUNTS
Administrative privilege should not be in use for routine work, where compromise is likeliest.
WHAT TO ESTABLISH
That administrators use ordinary accounts for ordinary work.
WHAT TO LIMIT MOST TIGHTLY
Financial systems and payment authority Customer and personal data System administration Anything that can grant further access
WHY THAT LAST CATEGORY
The ability to grant access is the ability to reach everything eventually.
WHAT TO ESTABLISH ABOUT TEMPORARY ACCESS
That it expires.
WHY
Temporary access granted without an end date is permanent.
WHAT TO USE
Time-limited grants, where the system supports it.
WHAT TO ESTABLISH ABOUT APPROVAL
Who approves access to what.
WHY
Access granted by whoever was asked produces inconsistency.
WHAT TO RECORD
Every grant, who approved it, and why.