Files
policies/Security/access_control_guidance.md
T

2.4 KiB

Access Control & Least Privilege Guidance

Document owner: [Owner/Role]
Approved by: [Steering Committee / CISO]
Effective date: [YYYY-MM-DD]
Review cadence: [Annually]


1. Purpose & Scope

Implementation guidance for the Access Control & Least Privilege Policy. Applies to IT/IAM, managers, and system/data owners.


2. Role Design — How To

  • Start from job function, not from current access ("what does a Support Engineer need" not "what does Alice currently have" — the latter just codifies drift).
  • Use Entra ID/Azure AD groups or equivalent RBAC roles; avoid direct resource ACLs for anything beyond a one-off, time-bound exception.
  • Keep the number of distinct roles small — role sprawl is as bad as ad hoc grants; if two roles differ by one permission, question whether they should be one role with a scoped exception.

3. Joiner-Mover-Leaver — Practical Flow

  1. Joiner: HR system triggers IAM provisioning workflow on start date; access live day 1, not requested ad hoc by the new hire's manager over chat.
  2. Mover: Role change in HR system triggers automatic review — old role's access removed, not left "just in case."
  3. Leaver: Termination in HR system triggers same-day deprovisioning; involuntary terminations trigger immediate (not end-of-day) revocation, coordinated with the immediate manager.

4. Access Review — Worked Example

Account Type Reviewer What to Check
Privileged/Admin Access Owner + manager Still needed? Still least-privilege scoped? Any dormant admin sessions?
Standard User Manager Role still matches job function? Any accumulated ad hoc grants to fold into role or revoke?
Service Account System owner Still in use? Rotation current per Secrets & Key Management Policy?

5. Checklist

Joiner-mover-leaver automated from HR system, not manual ticket-only.
Privileged access reviewed quarterly, standard semi-annually.
Separation-of-duties matrix documented for finance/production-deploy roles.
Dormant accounts flagged per Password Policy §2.11 (45-day inactivity).
Ad hoc/direct grants logged and swept into the next access review.


6. References