Administrative rights.
THE PRINCIPLE
The minimum access necessary, for the shortest time necessary.
WHAT TO AVOID
Everyone holding administrative rights Shared administrative accounts Permanent elevation
WHY SHARED ACCOUNTS FAIL
Nothing is attributable, and the credential is never changed.
WHAT TO PROVIDE INSTEAD
Individual accounts, with elevation when required.
WHAT TO LOG
Every use of elevated privilege.
WHAT TO RESTRICT MOST TIGHTLY
Production database access Deployment capability Access to secrets The ability to change access
WHAT TO REQUIRE FOR PRODUCTION DATABASE ACCESS
A reason, and ideally a second person aware.
WHY
Direct database changes bypass every safeguard the application provides.
WHAT TO PREFER
A tool or command performing the change, reviewed and repeatable.
WHAT TO REVIEW QUARTERLY
Every account, on every system Every key issued Every service with access
WHAT YOU WILL FIND
Access granted for a task that finished long ago.