Who can do what.
THE PRINCIPLE
Individual accounts, minimum permissions, reviewed regularly.
WHAT TO AVOID
Shared logins Everyone holding administrative rights Access granted for convenience
THE ADMINISTRATIVE RIGHTS POINT
Administrative access in a cloud account can create resources, change configuration and incur cost.
Restrict it tightly.
WHAT TO SET UP
A second authentication step, required Roles appropriate to each person Separate credentials for automated processes
WHAT TO DO ABOUT AUTOMATED ACCESS
Use dedicated credentials with limited permissions.
Never a person's credentials.
WHAT TO ROTATE
Keys and credentials used by software, periodically.
WHAT TO MONITOR
Who logged in and from where Resources created Permission changes
WHAT TO REVIEW QUARTERLY
Every account, every role, every key.
WHEN SOMEONE LEAVES
Remove access the same day, across every cloud service.
WHAT TO RECORD
What each person has, so removal is complete.