Credentials the business depends on.
WHY IT BELONGS HERE
Access held by individuals is lost when they leave, and shared informally it cannot be controlled.
WHAT THE PROBLEM IS
Accounts created by one person, known only to them.
WHAT THAT CAUSES
Lost access to critical services Inability to remove departed people No visibility of what exists
WHAT TO ESTABLISH
A record of every service the business uses.
WHAT TO RECORD
The service What it is used for The account it is registered to Who has access What it costs and when it renews
WHAT TO USE FOR CREDENTIALS
A password manager, with shared access controlled.
WHY NOT A DOCUMENT
Documents containing passwords circulate and are never updated.
WHAT TO AVOID
Passwords in shared messages Passwords written where others can see The same password across services Personal accounts used for business services
WHY PERSONAL ACCOUNTS MATTER MOST
The business does not control them.
WHAT TO ESTABLISH
That business services are registered to business accounts.
WHAT TO DO WHEN SOMEONE LEAVES
Remove their access, on the last day Change any credential they knew Transfer ownership of anything registered to them
WHY THE SAME DAY
It is the standard failure, and it leaves exposure open indefinitely.
WHAT TO MAINTAIN
A list of what each person has access to.
WHY
It is what makes removal complete rather than partial.
WHAT TO REVIEW PERIODICALLY
Who has access to what, against who should.
WHAT TO KEEP SECURELY
Emergency access, available to more than one person.