Knowledgebase

Managing Access for Contractors and Third Parties Print

  • 0

People outside the organisation.

WHY IT REQUIRES PARTICULAR ATTENTION

External access is granted broadly, monitored lightly and removed late.

WHAT TO ESTABLISH BEFORE GRANTING ANY

What they actually need For how long Who authorised it Who is responsible for them internally

WHY AN INTERNAL OWNER

External access without an internal owner is never reviewed or removed.

WHAT TO GRANT

The minimum necessary, for the period necessary.

WHAT TO ESTABLISH

An expiry date on every external grant.

WHY

It is the only reliable way external access ends.

WHAT TO AVOID

Giving contractors accounts identical to employees Shared accounts for a supplier's staff Permanent access for occasional work

WHY SHARED SUPPLIER ACCOUNTS

Actions cannot be attributed and departures at the supplier are unknown to you.

WHAT TO REQUIRE

Individual accounts for each person.

WHAT TO ESTABLISH

Notification when their staff change.

WHAT TO ESTABLISH ABOUT REMOTE ACCESS

How they connect What they can reach Whether sessions are recorded

WHY RECORDING

Third-party access to sensitive systems warrants a record.

WHAT TO ESTABLISH CONTRACTUALLY

Their security obligations Restrictions on sharing access Notification of incidents Return or destruction of data

WHAT TO REVIEW

External access, more frequently than internal.

WHY

Engagements end without anyone informing the people who manage access.

WHAT TO DO AT THE END OF ANY ENGAGEMENT

Remove access immediately Change any shared credentials Verify removal

WHAT TO MAINTAIN

A list of every external party with access.

WHY

It is the list nobody has and it is where forgotten access lives.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot