Who can do what.
THE PRINCIPLE
Each person has their own account with the minimum access their work requires.
WHY INDIVIDUAL ACCOUNTS
Actions are attributable Access can be removed for one person A compromise affects one account
WHAT SHARED LOGINS COST
No attribution, no selective removal, and a password nobody ever changes.
WHAT TO REVIEW QUARTERLY
Every account on every system Every application with permissions Every key and credential issued
WHAT YOU WILL FIND
Accounts for people who left Access granted for a one-off task Applications authorised and forgotten
WHAT TO REMOVE
Anything you cannot account for.
WHEN SOMEONE LEAVES
Everything, the same day.
Keep a list of every system each person was given access to; that list is what you work through.
WHAT TO DOCUMENT
Who has what, and why.
WHAT TO AUTOMATE
Nothing about the decision. The review must be deliberate.