Access control
o Challenges when implementing access control
Number of different subjects
Users will need different levels of access depending on their job role
Types of objects or resources available
Objects will require different levels of classification
The number of resources that include identity data
This requires constant access management
Business environment
Constantly changing in its access control needs
New employees/ users or systems
Strict principles must be put in place until new users are properly
assigned with the appropriate access
o Principles
Principle of the lease privileged
If the subject has not been put into a permission group, the subject
should not be able to access the resourced
Separation of duties
Duties should be properly separated
Need to know
Individuals or employees should ONLY be given access to the
resource, they will only need to do their job.
o Access criteria for objects
Roles
Job roles define duties employees have and what access is required
to complete them.
Groups
Some job roles are part of a larger group that allows specific access
rights
Access to some objects will be restricted to specific times
Transaction type
Subjects may be able to access resources depending on the actions
they require
o Practises
Enforce need to know and least privileged principles straight away
Monitor the use or carefully assign usage to those with powerful
permissions
Block or delay access after a number of unsuccessful login attempts
Remove users that leave the organisation immediately
Suspend inactive accounts after a month
Remove features and series that are no longer required
Ensure that default passwords are replaced as soon as possible
Limit or monitor rules which are broad
Privilege creep
This is where users gradually accumulate access rights beyond what
they need for their job
Ensure that login IDs are not descriptive of job roles
Enforce need to know and least privileged principles straight away
o Challenges when implementing access control
Number of different subjects
Users will need different levels of access depending on their job role
Types of objects or resources available
Objects will require different levels of classification
The number of resources that include identity data
This requires constant access management
Business environment
Constantly changing in its access control needs
New employees/ users or systems
Strict principles must be put in place until new users are properly
assigned with the appropriate access
o Principles
Principle of the lease privileged
If the subject has not been put into a permission group, the subject
should not be able to access the resourced
Separation of duties
Duties should be properly separated
Need to know
Individuals or employees should ONLY be given access to the
resource, they will only need to do their job.
o Access criteria for objects
Roles
Job roles define duties employees have and what access is required
to complete them.
Groups
Some job roles are part of a larger group that allows specific access
rights
Access to some objects will be restricted to specific times
Transaction type
Subjects may be able to access resources depending on the actions
they require
o Practises
Enforce need to know and least privileged principles straight away
Monitor the use or carefully assign usage to those with powerful
permissions
Block or delay access after a number of unsuccessful login attempts
Remove users that leave the organisation immediately
Suspend inactive accounts after a month
Remove features and series that are no longer required
Ensure that default passwords are replaced as soon as possible
Limit or monitor rules which are broad
Privilege creep
This is where users gradually accumulate access rights beyond what
they need for their job
Ensure that login IDs are not descriptive of job roles
Enforce need to know and least privileged principles straight away