Security steps when a person joins.
BEFORE THEY START
Decide what access the role requires Prepare individual accounts, not shared ones Prepare or configure their device
ON DAY ONE
Set up accounts with unique credentials Require the second step Add them to the password manager
Configure the device: updates, lock, encryption, security software
BRIEF THEM ON
Not clicking links in messages about accounts Never sharing verification codes The verification rule for payments and access changes Who to tell when something seems wrong That reporting a mistake is welcomed
RECORD
Every system they were granted access to
THAT RECORD
Is what you work through when they leave.
WITHIN THE FIRST WEEKS
Check they are actually using the password manager Answer whatever they were unsure about
WHAT NOT TO DO
Give broad access because it is simpler Share an existing login to save time
WHAT TO REVIEW
Whether their access still matches the role, quarterly.