A bank, a hotel and a hospital have the same access problem

Six questions, asked of every business. What changes is who is asking, and why.

Access security is the same discipline in every business, and the questions it answers do not change with what you sell. Who are your people, and where does the authoritative list of them live. What can each of them reach, and who decided that. What happens on the machines they use, and on the phones you do not own. Where can your data go, and by which routes. Who reaches the servers and databases that run the business, and what did they do there. And can you produce a record of all of it for someone who arrives to check.

Ask two systems and get two answers

Every access decision starts from a list of people, and most businesses have several. A group with four plants under three legal entities has a directory per entity. A shared services centre has one workforce serving several businesses. An acquisition arrives with its own directory and stays that way for years. Until one list is authoritative, every one of these questions gets a different answer depending on which system you ask.

Nothing removes access unless something checks

Access granted by role is predictable and access granted by request is not, and every business runs both. The question is whether the grant was decided by someone accountable for the resource, recorded with a reason, and taken back when the role changed. Most estates can answer the first part and not the second.

A control that needs to reach the device is not a control

Laptops that leave the building, phones the business does not own, terminals shared across a shift, and machines in a plant or a branch with nobody technical nearby. Control that depends on reaching the device fails exactly when it matters. Control that sits on the device holds whether or not anything can reach it.

Email is covered. The browser is not.

Email usually has something watching it, because email gateways have existed for twenty years, and removable media sometimes does. The browser, a cloud folder shared with a link, and a credential committed into code usually have nothing, because no separate purchase ever covered them.

A shared root password is an unanswerable question

Production servers, databases, the cloud console, network gear. A small number of people reach them and the damage is unbounded. A shared credential among them leaves no record of who used it, and an administrator with standing access has it on a Sunday night as much as a Tuesday morning.

You cannot start recording retrospectively

Someone will arrive and ask: a regulator on a schedule, a client under a contract, a customer's security review before they sign, an auditor for a certification you chose. They will name a period that has already closed. Whether you can answer depends on what was being recorded while it was happening.

A regulator asks once a year. A client asks at every renewal.

A bank answers all six to a regulator on a schedule. A BPO answers them to each client separately, in the language of that client's contract. A university answers them for a population that turns over by a third every year. A manufacturer answers them across a shop floor, a design office and four plants under three legal entities.

See how it works.