Looking for 'top tips' or pieces of advice you would give to someone newly responsible for an organization’s access management security?

Dani AI

Generated

Practical, prioritized guidance for someone newly responsible for access management. Start with a short, measurable roadmap: 0–30 days — inventory all user, admin, service, and privileged accounts and capture owners; 30–60 days — force multi-factor authentication for exposed and admin accounts, remove orphaned/dormant accounts, enable logging; 60–90 days — automate provisioning/deprovisioning, implement role/attribute‑based access, and codify review cycles. Treat the inventory and regular reviews as the foundation for everything that follows. CIS Controls v8 — Account Management. (cisecurity.org)

Put strong authentication and central identity controls in place next. Centralize authentication via an IdP/SSO, require phishing‑resistant MFA (passkeys or hardware tokens) for admin and externally exposed apps, block breached passwords, and prefer password managers over arbitrary rotation policies. Use published assurance guidance when choosing authenticators and levels. and the CIS access controls both provide concrete safeguards to implement. ()

Lock down privileged access and move toward Zero Trust. Limit the number of privileged users, use dedicated admin accounts and Privileged Access Workstations, apply Just‑In‑Time / Just‑Enough‑Privilege provisioning, record and monitor privileged sessions, and make access decisions based on identity, device posture, and context instead of implicit trust. See Zero Trust architecture guidance for design patterns. NIST SP 800‑207 (Zero Trust Architecture). (csrc.nist.gov)

Building on ’s contractual caution, involve legal and procurement early: require security SLAs and attestations (SOC 2/ISO 27001), defined incident notification and remediation timelines, right to audit, clear deprovisioning and data‑return terms, and liability/indemnity limits tied to organizational risk tolerance. Treat contracts and supply‑chain controls as part of access security, not an afterthought. NIST SP 800‑161 — Supply Chain Risk Management. (nist.gov)

@Sammy, while I want to know why all these posts I do have advice.

Be sure you are not legally held responsible for the breaches. Read carefully what you sign. I had one deal I bowed out since the contract had me signing on to pay for losses if the product didn't produce the expected economic returns. Another had me taking liability for the company product.

Cover your bases, don't sign what you don't understand.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.