Utarbeidet med KI.
A semiannual access review takes a few hours and eliminates most of the accumulated risk.
Who has which role. Start with the system administrators—the list is usually longer than expected.
No login activity in the past ninety days. These are usually former employees or people who have changed roles.
They are systematically forgotten because no manager owns them. Find out what each one is used for and who owns it.
Ask them to confirm or decline. Set a deadline. Without a deadline, the responses will never come.
The standard should be that access which no one confirms is removed. The opposite rule results in a review with no effect.
If the same problem keeps recurring—for example, if a change of role never triggers a clean-up—it is the role-change procedure that needs to be fixed, not the review.
Still et spørsmål eller del hva som hjalp deg.
Publisert 30.8.2024
I løpet av de siste årene har hybride arbeidssteder blitt normen for mange. I takt med dette skiftet har både de IT-funksjonelle og sikkerhetsmessige behovene endret seg. Her er noen gode råd fra vår IT- og sikkerhetsleder om hvordan organisasjoner bør gå frem for å oppnå sikker IT i en hybrid verden.
Les merHar du et spørsmål eller en erfaring å dele?
Bli den første som bidrar.