People outside the organisation.
WHY IT REQUIRES PARTICULAR ATTENTION
External access is granted broadly, monitored lightly and removed late.
WHAT TO ESTABLISH BEFORE GRANTING ANY
What they actually need For how long Who authorised it Who is responsible for them internally
WHY AN INTERNAL OWNER
External access without an internal owner is never reviewed or removed.
WHAT TO GRANT
The minimum necessary, for the period necessary.
WHAT TO ESTABLISH
An expiry date on every external grant.
WHY
It is the only reliable way external access ends.
WHAT TO AVOID
Giving contractors accounts identical to employees Shared accounts for a supplier's staff Permanent access for occasional work
WHY SHARED SUPPLIER ACCOUNTS
Actions cannot be attributed and departures at the supplier are unknown to you.
WHAT TO REQUIRE
Individual accounts for each person.
WHAT TO ESTABLISH
Notification when their staff change.
WHAT TO ESTABLISH ABOUT REMOTE ACCESS
How they connect What they can reach Whether sessions are recorded
WHY RECORDING
Third-party access to sensitive systems warrants a record.
WHAT TO ESTABLISH CONTRACTUALLY
Their security obligations Restrictions on sharing access Notification of incidents Return or destruction of data
WHAT TO REVIEW
External access, more frequently than internal.
WHY
Engagements end without anyone informing the people who manage access.
WHAT TO DO AT THE END OF ANY ENGAGEMENT
Remove access immediately Change any shared credentials Verify removal
WHAT TO MAINTAIN
A list of every external party with access.
WHY
It is the list nobody has and it is where forgotten access lives.