Access & identity (IAM): auditability and control in infrastructure
IAM is fundamental to both security and operations. If it is unclear who has which permissions, for how long and how access is controlled, the infrastructure remains difficult to audit and unnecessarily risky.
IAM is the backbone of both security and operations.
Without MFA, audit logs and removal of shared access rights, changes are unauditable and incidents are more expensive.
Key questions
- Privileged accounts: who has admin/root access, where are the "break-glass" accounts and how are they used?
- Access lifecycle: how are authorisations granted, changed and revoked (joiner/mover/leaver)? Is the process linked to HR and the identity provider?
- Least privilege: are roles and permissions based on responsibilities, or is excessive access granted by default?
- MFA and strong authentication: is MFA mandatory for privileged roles, VPN, admin consoles and critical systems?
- Audit and traceability: do we have centralised audit logs (who changed what, when, from where) and can we find them in the event of an incident?
- Secrets & certificates: where are secrets stored (API keys, tokens, certificates), who rotates them and how often?
- Suppliers: is supplier access granted just in time (JIT), reviewed regularly and separated from internal accounts?
Typical risks in practice
- Shared accounts and passwords: there is no attribution of changes and incidents cannot be explained retrospectively.
- Permanent admin rights: privileged roles are assigned by default, without approval or expiry.
- Missing access reviews: entitlements remain unchanged for years, even when a person changes team or a supplier relationship ends.
- Secrets in repositories: keys in code or in non-rotating and ownerless configurations.
- Audit logs out of reach: logs are not centralised or are kept too short for investigation.
The biggest shift will often come from the "minimum standard": personal accounts, MFA, separate privileged roles, centralised audit logs and regular reviews of authorisations.
Related:
Do you need help?
To design or stabilise access and identity in your infrastructure, get in touch with us – we can advise you on how to do it.
Contact WOV Tech