Accounts review
An account is defined by an identifier, a password and sometimes authenticating methods and external access.
Companies use many different accounts, all of which have their own permissions, and it is therefore important that these are reviewed on a regular basis:
- One individual might have several accounts – is this really justified?
- Is it possible to effectively differentiate between global, user, administrator and operational service accounts?
- Is an account active, suspended or dormant?
- Is an account linked to the correct operational level, role and job profile?
- Has the role hierarchy been observed?
These questions need to be addressed to ensure that access to the IS is secure and compliant with regulations.
Nowadays, companies need identity and access management tools to effectively manage risks.
Top of page