Access outside your own systems.
WHY IT DIFFERS
Services are adopted independently, and access is granted in each separately.
WHAT PRODUCES SPRAWL
Individuals subscribing to services Departments adopting tools Trials becoming permanent Services nobody records
WHAT THAT MEANS
Access exists in places the organisation does not know about.
WHAT TO ESTABLISH
What services are actually in use.
HOW
Examine expenditure, and ask.
WHY EXPENDITURE
Subscriptions appear on cards and invoices.
WHAT TO ESTABLISH
A route for adopting new services, with recording.
WHY
Prohibition produces concealment; a route produces visibility.
WHAT SINGLE SIGN-ON PROVIDES
Access to many services through one identity, centrally controlled.
WHY IT MATTERS
Removal in one place removes access everywhere.
WHAT TO ESTABLISH
Which services support it, and connect them.
WHAT TO PRIORITISE
Services holding sensitive data Services many people use
WHAT TO ESTABLISH ABOUT SERVICES THAT DO NOT SUPPORT IT
That they are recorded and reviewed individually.
WHAT TO ESTABLISH ABOUT THIRD-PARTY CONNECTIONS
What applications have been granted access to your data by users.
WHY
Users authorise applications, and those authorisations persist.
WHAT TO REVIEW
Connected applications and their permissions.
WHAT TO REMOVE
Anything unnecessary or unrecognised.
WHAT TO ESTABLISH ABOUT ADMINISTRATIVE ACCESS
Who administers each service.
WHAT TO VERIFY
That it is not one person, and not a personal account.
WHAT TO ESTABLISH
Multi-factor authentication on every administrative account.