Identity and Access Management Policy
Document control
| Field | Value |
|---|---|
| Document status | Active policy document |
| Owner | Security / Operations |
| Approver | Management |
| Review frequency | Annual or on material change |
| Classification | Customer-shareable |
Purpose
Ensure access to systems and data is authorized, traceable, least-privileged, and removed when no longer required.
Access principles
Access must be based on business need, approved by an owner, limited to the minimum privileges required, and reviewed periodically. Shared accounts should be avoided. Privileged access requires additional scrutiny and monitoring.
Provisioning
Access requests should capture user, role, system, business purpose, approval, duration, and privilege level. Access should be granted through role-based groups where feasible.
Authentication
Strong authentication must be used for business systems. MFA should be used for administrative, remote, cloud, repository, and sensitive system access where supported.
Privileged access
Administrator permissions must be restricted to authorized personnel, used only for approved purposes, and reviewed more frequently. Emergency access should be logged and reviewed.
Joiner/mover/leaver process
Access must be granted during onboarding, adjusted when roles change, and revoked promptly during offboarding or contract completion.
Service accounts and API keys
Service accounts must have owners, purpose, limited permissions, credential rotation, and revocation process. Keys must not be shared or stored insecurely.
Evidence to maintain
Access request/approval records, access review evidence, MFA evidence, privileged user list, offboarding checklist, and service account inventory.