Managing access at scale.
WHY INDIVIDUAL GRANTS FAIL
Access assigned person by person cannot be reviewed or reasoned about.
WHAT ROLE-BASED ACCESS MEANS
Permissions attached to roles, and people assigned to roles.
WHAT IT PROVIDES
Consistency Reviewability Simple changes when a role's requirements change Clear removal when someone changes role
WHAT TO ESTABLISH
The roles that actually exist in the organisation.
WHAT TO DEFINE FOR EACH
What systems and permissions it carries.
WHAT TO AVOID
Roles defined so narrowly that there is one per person Roles so broad that they grant unnecessary access
WHY THE FIRST
It is individual assignment with extra steps.
WHAT TO ESTABLISH
A manageable number of roles covering most people.
WHAT TO DO ABOUT EXCEPTIONS
Grant them individually, and record them as exceptions.
WHY RECORD
Exceptions accumulate invisibly otherwise.
WHAT TO REVIEW
Exceptions, periodically.
WHAT TO ESTABLISH ABOUT COMBINED ROLES
Whether holding two roles creates a problem.
WHY
Some combinations defeat separation of duties.
WHAT EXAMPLES LOOK LIKE
Creating a supplier and approving payments Creating a user and approving their access Recording a transaction and reconciling it
WHAT TO ESTABLISH
Which combinations are prohibited.
WHAT TO CHECK
Whether anyone currently holds them.
WHAT TO DO
Separate them, or apply compensating controls.
WHAT TO MAINTAIN
The definition of each role, documented.