The accounts that matter most.
WHY THEY MATTER DISPROPORTIONATELY
They can reach everything, change anything and remove evidence.
WHAT COUNTS AS PRIVILEGED
System and domain administration Cloud and hosting account administration Database administration Network equipment access Financial system administration Anything that can grant access to others
WHAT TO ESTABLISH
Who holds each, and whether they need it.
WHY
Privileged access is granted for a task and retained indefinitely.
WHAT TO LIMIT
The number of people holding it.
WHAT TO ESTABLISH
Separate accounts for privileged work.
WHY
Routine activity is where compromise occurs, and it should not carry privilege.
WHAT TO REQUIRE
Multi-factor authentication on every privileged account.
WHAT TO ESTABLISH ABOUT USE
That privileged access is used only when required.
WHAT TO LOG
Privileged actions.
WHY
They are what matters in any investigation.
WHAT TO ESTABLISH
That logs cannot be altered by those they record.
WHY
Otherwise they prove nothing.
WHAT TO CONSIDER
Granting privilege temporarily when needed rather than permanently.
WHAT THAT PROVIDES
Reduced exposure, and a record of when it was used.
WHAT TO ESTABLISH ABOUT EMERGENCY ACCESS
A route that works when normal systems fail.
WHY
Recovery requires access that does not depend on what has failed.
WHAT TO ESTABLISH
Credentials held securely, accessible to more than one person, with use recorded.
WHY MORE THAN ONE
A single holder who is unavailable blocks recovery.
WHAT TO REVIEW
Who holds privileged access, frequently.