Identity & Access Management
RBAC & Access Policy Design
Access decisions follow written policy instead of accumulated exceptions.
The problem
Access policy in most organisations is an accumulation of exceptions. Each one was reasonable when it was granted; together they mean nobody can state what the rules are, and no assessor can verify them.
How we approach it
We model roles and entitlements against how the organisation actually works, design the access policy for wired, wireless and remote paths, and put a review process around exceptions so the model does not decay back into a list.
What the work covers
- Role and entitlement modelling
- Policy design for wired, wireless, and VPN
- Exception review and cleanup