Safeguards
Privileged access
How do you secure administrator accounts?
Privileged access means the accounts that may do everything: administrators, service accounts, the access of your IT provider. Whoever takes one of them over holds the business in their hands.
The first principle is separation. Anyone who reads email and browses the web every day should not do so with an account that carries administrator rights. A separate account for administration, used only for that, prevents one click on an attachment from opening the whole network.
The second principle is limitation. Rights are granted for the duration of the task and withdrawn afterwards. Permanent administrator rights held just in case are convenient and expensive.
The third principle concerns remote maintenance. Your provider's access is privileged access. It belongs behind a second factor, it belongs logged, and it belongs closed as soon as the co-operation ends.
All terms in the knowledge base
Note: This entry reflects the state of knowledge to the best of our understanding and serves as general orientation. It is not legal advice. What counts is always the version currently in force at the responsible body, for example dsb.gv.at, nis.gv.at or enisa.europa.eu.
From the term to practice
Where does your business actually stand?
The IT Check reviews your IT across 8 audit areas with more than 100 individual checks and delivers documented findings with a prioritised action plan. From 1,299 € excl. VAT. The first call takes 20 minutes and carries no charge.