What protection is expected.
WHAT THE REQUIREMENT GENERALLY IS
Measures appropriate to the risk.
WHAT DETERMINES APPROPRIATE
The sensitivity of the data The scale The potential harm The state of available technology The cost
WHAT THE BASELINE USUALLY INCLUDES
Access control, with individual accounts Strong authentication Encryption in transit Encryption at rest, for sensitive data Backups, tested Patching Logging of access Staff training
WHY INDIVIDUAL ACCOUNTS MATTER MOST
Shared logins make attribution impossible, which undermines every other control.
WHAT ACCESS CONTROL SHOULD ACHIEVE
People able to see only what their role requires.
WHAT TO REVIEW
Who has access to what, periodically.
WHAT TO REMOVE PROMPTLY
Access for anyone who has left.
WHAT ENCRYPTION AT REST PROTECTS
Data on stolen equipment or backups.
WHAT IT DOES NOT PROTECT
Anything reachable through a running system.
WHY THAT NEEDS SAYING
It is frequently claimed as a general defence.
WHAT TO DOCUMENT
The measures in place, and the reasoning.
WHY
Accountability requires demonstrating them.
WHAT TO TEST
Backups, access controls, and the incident process.
WHAT TO AVOID
Measures documented but not implemented.