Security architecture and operations

Identity and Access Management Strategy

Identity and access management strategy establishes how access is granted, reviewed and removed across your systems, who approves it, and how the organization can evidence that the process is actually followed.

Schedule a Confidential Consultation What you receive

At a glance

Part of
The design and running of the controls a strategy depends on.
Engaged as
A defined piece of work, or as part of an ongoing vCISO engagement.
Sits under
Executive ownership of the cybersecurity program.

Timing

When organizations engage this

  • An assessment or audit asked for evidence of periodic access reviews.
  • An employee or contractor departure raised doubt about whether access was fully removed.
  • Administrative access is held by individuals, with no record of who granted it or why.
  • Multi-factor authentication is partially deployed and nobody can say where the gaps are.
  • A merger, acquisition or system consolidation is about to combine two access models.

What you receive

  • Access inventory for critical systems with privileged accounts identified
  • Documented joiner, mover and leaver process with named owners
  • Authentication standard including a register of exceptions and their remediation dates
  • Access review procedure and evidence format

Why this comes up

Access accumulates. People change roles and keep what they had; contractors finish and their accounts remain; a system is adopted and its permissions are set by whoever configured it. Nobody decides that this should happen, it is simply what occurs without a process.

It surfaces in three places: an assessment asks for evidence of access reviews, an incident investigation finds a dormant account was used, or an employee leaves and nobody is confident everything was revoked.

The service

What this engagement is

Who it is for

  • Organizations that cannot currently produce an accurate list of who has access to critical systems.
  • Companies where offboarding depends on somebody remembering every system.
  • Businesses facing an assessment that requires evidence of periodic access review.
  • Leadership teams concerned about administrative access sitting with individuals rather than roles.

A strategy for identity across the systems that matter, rather than a tool selection exercise. It covers how joiners, movers and leavers are handled, how privileged access is controlled and monitored, and how access reviews are performed and evidenced.

The emphasis is on decisions the organization can sustain. A review process requiring managers to certify hundreds of entitlements quarterly will be rubber-stamped; one scoped to the access that matters will actually be performed.

Scope

What Heights does

  • Access inventory across critical systems

    Who has access to what, at what level, and how each grant was authorized.

  • Joiner, mover and leaver process

    How access is provisioned on hire, adjusted on role change, and removed on departure, with the movers step, which is the one most often missing.

  • Privileged access control

    How administrative rights are granted, constrained, monitored and periodically re-justified.

  • Authentication standards

    Where multi-factor authentication is required, where exceptions exist and why, and what the plan is for closing them.

  • Access review that is actually performed

    A review cycle scoped so reviewers can engage with it meaningfully, producing evidence an assessor will accept.

Alignment

Frameworks this work touches

Establishing which of these apply to you

NIST CSF
A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
ISO 27001
An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
SOC 2
An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
SOX
Access, change management and IT operations controls supporting the reliability of financial reporting. Assessed annually as part of internal control over financial reporting.
HIPAA
The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.

Identity decisions create friction, and friction needs an owner with the standing to hold the line or to grant a considered exception. A vCISO makes those calls and records them, rather than leaving each one to be re-argued.

Read about vCISO leadership

Getting started

How an engagement begins

The same three steps whichever service you start with.

  1. A confidential conversation

    What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.

  2. Scope agreed in writing

    What Heights will do, what stays with you, the working rhythm, and how progress will be reported.

  3. Work begins

    Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.

Questions we are asked about this

Broader questions about executive security leadership are answered on the vCISO page.

Do we need to buy an identity management platform?

Not necessarily, and not first. Many organizations get most of the available benefit from process and configuration changes in tools they already own.

A platform bought before the process is defined tends to automate the existing confusion. If tooling is genuinely warranted, the strategy makes the requirement clear enough to evaluate options properly.

How often should access be reviewed?

Quarterly for privileged and high-sensitivity access, annually for the broader population, is a common and defensible pattern. Departures and role changes should trigger action immediately rather than waiting for a cycle.

The right frequency is the one that will actually be performed with attention. A demanding cycle that gets rubber-stamped provides evidence without providing assurance.

What about access held by our outside providers?

Provider access should be in the same inventory as employee access, and often deserves more scrutiny, it is frequently privileged, shared between technicians, and outside your joiner-mover-leaver process entirely.

This is a point where identity work and third-party oversight meet, and it is usually handled together.

Talk through Identity and Access Management Strategy with us.

Tell us what prompted the enquiry and what the organization is working toward. You will get a straight view of the right scope, including when that is smaller than you expected.