Protecting business data.
WHAT TO ESTABLISH
Roles matching actual job functions Permissions granted to roles, not individuals Approval for role assignment
WHAT SEGREGATION OF DUTIES REQUIRES
Conflicting permissions not held by one person.
WHAT THE COMMON CONFLICTS ARE
Creating a supplier and approving a payment Entering a transaction and approving it Administering users and transacting
WHAT TO CONFIGURE
Rules preventing those combinations.
WHAT TO REVIEW
Who holds them, periodically.
WHAT ADMINISTRATIVE ACCESS REQUIRES
Restriction to few people Separate accounts from their ordinary ones Logging of everything done
WHY SEPARATE ACCOUNTS
It distinguishes administrative action from routine work.
WHAT AUTHENTICATION SHOULD REQUIRE
Individual accounts, never shared Strong credentials Additional verification for sensitive access
WHY SHARED ACCOUNTS ARE UNACCEPTABLE
They destroy accountability entirely.
WHAT TO LOG
Access to sensitive data Changes to permissions Data exports Administrative actions
WHY EXPORTS SPECIFICALLY
They are the route by which data leaves.
WHAT TO MONITOR
Unusual access patterns Access outside working hours Large exports
WHAT TO DO ON DEPARTURE
Revoke immediately, and verify.