Using Roles and Groups Print

  • 0

Managing access at scale.

WHY INDIVIDUAL GRANTS FAIL

Access assigned person by person cannot be reviewed or reasoned about.

WHAT ROLE-BASED ACCESS MEANS

Permissions attached to roles, and people assigned to roles.

WHAT IT PROVIDES

Consistency Reviewability Simple changes when a role's requirements change Clear removal when someone changes role

WHAT TO ESTABLISH

The roles that actually exist in the organisation.

WHAT TO DEFINE FOR EACH

What systems and permissions it carries.

WHAT TO AVOID

Roles defined so narrowly that there is one per person Roles so broad that they grant unnecessary access

WHY THE FIRST

It is individual assignment with extra steps.

WHAT TO ESTABLISH

A manageable number of roles covering most people.

WHAT TO DO ABOUT EXCEPTIONS

Grant them individually, and record them as exceptions.

WHY RECORD

Exceptions accumulate invisibly otherwise.

WHAT TO REVIEW

Exceptions, periodically.

WHAT TO ESTABLISH ABOUT COMBINED ROLES

Whether holding two roles creates a problem.

WHY

Some combinations defeat separation of duties.

WHAT EXAMPLES LOOK LIKE

Creating a supplier and approving payments Creating a user and approving their access Recording a transaction and reconciling it

WHAT TO ESTABLISH

Which combinations are prohibited.

WHAT TO CHECK

Whether anyone currently holds them.

WHAT TO DO

Separate them, or apply compensating controls.

WHAT TO MAINTAIN

The definition of each role, documented.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot