Auditing Who Has Access Print

  • passwordsmanagement, passwords, permissions, email, ftp, hacked, webhosting, guide
  • 0

The regular review.

HOW OFTEN

Quarterly.

WHAT TO REVIEW

Every user account on your site Every FTP account Every hosting account user Every email account Third-party services with access Applications with permissions granted SSH keys, if applicable

WHAT YOU WILL FIND

Accounts for people who left Accounts created for a one-off task Contractor accounts from old projects Applications authorised years ago Accounts nobody recognises

THAT LAST ONE

Investigate immediately. It may indicate compromise.

WHAT TO DO

Remove anything you cannot account for.

Back up first, and check nothing depends on it.

FOR APPLICATIONS WITH PERMISSIONS

Review what each can do and remove those unused.

WHAT TO RECORD

The review, what you found, what you removed.

WHY

It demonstrates the review happened, and shows patterns over time.

WHAT TO DO IF THE LIST IS LONG

That is normal on a neglected account. Work through it.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot