Technology · Security · Component
Identity and access arrangements
How people and systems prove who they are, what privileged accounts exist, and how access follows people as they join, move and leave.
The deliverable
What it is
With most systems rented and reached over the internet, identity has become the effective perimeter. A large share of breaches begin with a stolen or reused credential, which makes multi-factor authentication, single sign-on and the handling of privileged accounts the controls with the widest reach.
The decision about who should see which data belongs to Data Core under access; this component implements it in the systems. The two meet at the access review, where the policy and the accounts that actually exist are compared.
One level in
What it is made of
Each element is a constituent part of the component. Follow one to see the attributes it carries.
Authentication standard
How users and services sign in, where multi-factor authentication is required, and which exceptions exist.
3 attributes: Method · MFA coverage · Exceptions
LearnPrivileged accounts
Administrator and service accounts with broad reach, who holds them, and how their use is controlled.
3 attributes: Count · Holder · Last rotated
LearnJoiner, mover, leaver process
How access is granted on arrival, adjusted on a change of role, and removed on departure, and how quickly.
3 attributes: Time to remove access · Trigger · Last access review
Learn
Review the movers as well as the leavers. Access gathered across three roles is the quiet kind of excess.
The other components in security
Threat model
What is worth protecting, who might want it, and the plausible routes by which harm could arrive.
LearnSecurity control baseline
The recognised set of security controls the organisation has adopted, tailored to its threats, with the honest status of each.
LearnBackup and recovery plan
What is backed up, how quickly each critical system must return, and dated evidence that restoring actually works.
Learn