Managing Who Has Access Print

  • websitesecurityfundamentals, website, security, hacked, password, permissions, guide, howto
  • 0

Accounts and permissions.

THE PRINCIPLE

Each person has their own account, with the minimum access they need.

WHY INDIVIDUAL ACCOUNTS

Actions are attributable Access can be removed for one person A compromise affects one account

WHAT SHARED LOGINS COST

No attribution No way to remove one person A password everyone knows and nobody changes

WHAT LEVELS TO USE

Administrator only for those who genuinely need it Editor or equivalent for content The lowest level that allows the work

WHO SHOULD BE ADMINISTRATOR

As few people as possible.

REVIEWING ACCESS

Quarterly.

WHAT YOU WILL FIND

Accounts for people who left Accounts created for a one-off task Accounts nobody recognises

THAT LAST ONE

Investigate immediately.

WHEN SOMEONE LEAVES

Remove access the same day.

The most commonly neglected security action.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot