What's changed: Initial version
5.2Access management & privileged access
Covers access management, which controls who is allowed what in service operations-the principle of least privilege, the provisioning (granting) and periodic review (revocation) of privileges, privileged access management that handles powerful rights strictly, and the authentication that verifies identity-framed as an operator's judgment to prevent risks such as insider misuse and dangling leaver accounts.
Running a service safely rests on properly controlling "who can access which systems, and to what extent." Handing out too many privileges enlarges the damage from insider misuse and incidents, while being too restrictive halts work and harms the SLA. Moreover, if granted privileges are left unattended, leaver and transferee accounts persist and become a breeding ground for misuse. This section covers the principle of least privilege, the lifecycle of granting privileges (provisioning) and periodically reviewing them (recertification), privileged access management for especially powerful rights, and the authentication that verifies identity-framed as an operator's judgment.
5.2.1Least privilege and the access-rights lifecycle
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

