Limiting who sees what.
WHAT LEAST PRIVILEGE MEANS
Each person has access to only what their role requires.
WHY IT IS THE MOST EFFECTIVE SINGLE CONTROL
It limits the damage of every other failure.
WHAT TO ESTABLISH
What each role genuinely needs.
HOW
Ask what tasks they perform, and what data each requires.
WHAT TO AVOID
Granting broad access because it is simpler Copying an existing person's permissions Access granted temporarily and never removed
WHY THAT LAST ONE MATTERS
Permissions accumulate, and nobody reviews them.
WHAT TO IMPLEMENT
Individual accounts, never shared Role-based permissions Strong authentication Logging of access to personal data
WHY INDIVIDUAL ACCOUNTS ARE FOUNDATIONAL
Without attribution, no other control can be demonstrated.
WHAT TO REVIEW
Who has access to what, on a schedule.
HOW OFTEN
At least annually, and after any role change.
WHAT TO REMOVE IMMEDIATELY
Access for anyone who has left.
WHAT TO CHECK
That removal actually happened, across every system.
WHY
Departure processes routinely miss systems.
WHAT TO MAINTAIN
A list of systems holding personal data, for exactly this purpose.
WHAT TO LOG
Access to sensitive records.
WHAT TO REVIEW
Those logs, periodically.