Knowledgebase

Controlling Administrative and Privileged Access Print

  • 0

The accounts that matter most.

WHY THEY MATTER DISPROPORTIONATELY

They can reach everything, change anything and remove evidence.

WHAT COUNTS AS PRIVILEGED

System and domain administration Cloud and hosting account administration Database administration Network equipment access Financial system administration Anything that can grant access to others

WHAT TO ESTABLISH

Who holds each, and whether they need it.

WHY

Privileged access is granted for a task and retained indefinitely.

WHAT TO LIMIT

The number of people holding it.

WHAT TO ESTABLISH

Separate accounts for privileged work.

WHY

Routine activity is where compromise occurs, and it should not carry privilege.

WHAT TO REQUIRE

Multi-factor authentication on every privileged account.

WHAT TO ESTABLISH ABOUT USE

That privileged access is used only when required.

WHAT TO LOG

Privileged actions.

WHY

They are what matters in any investigation.

WHAT TO ESTABLISH

That logs cannot be altered by those they record.

WHY

Otherwise they prove nothing.

WHAT TO CONSIDER

Granting privilege temporarily when needed rather than permanently.

WHAT THAT PROVIDES

Reduced exposure, and a record of when it was used.

WHAT TO ESTABLISH ABOUT EMERGENCY ACCESS

A route that works when normal systems fail.

WHY

Recovery requires access that does not depend on what has failed.

WHAT TO ESTABLISH

Credentials held securely, accessible to more than one person, with use recorded.

WHY MORE THAN ONE

A single holder who is unavailable blocks recovery.

WHAT TO REVIEW

Who holds privileged access, frequently.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot