At a glance
- Part of
- The design and running of the controls a strategy depends on.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
Timing
When organizations engage this
- An assessment or audit asked for evidence of periodic access reviews.
- An employee or contractor departure raised doubt about whether access was fully removed.
- Administrative access is held by individuals, with no record of who granted it or why.
- Multi-factor authentication is partially deployed and nobody can say where the gaps are.
- A merger, acquisition or system consolidation is about to combine two access models.
What you receive
- Access inventory for critical systems with privileged accounts identified
- Documented joiner, mover and leaver process with named owners
- Authentication standard including a register of exceptions and their remediation dates
- Access review procedure and evidence format
Why this comes up
Access accumulates. People change roles and keep what they had; contractors finish and their accounts remain; a system is adopted and its permissions are set by whoever configured it. Nobody decides that this should happen, it is simply what occurs without a process.
It surfaces in three places: an assessment asks for evidence of access reviews, an incident investigation finds a dormant account was used, or an employee leaves and nobody is confident everything was revoked.
The service
What this engagement is
Who it is for
- Organizations that cannot currently produce an accurate list of who has access to critical systems.
- Companies where offboarding depends on somebody remembering every system.
- Businesses facing an assessment that requires evidence of periodic access review.
- Leadership teams concerned about administrative access sitting with individuals rather than roles.
A strategy for identity across the systems that matter, rather than a tool selection exercise. It covers how joiners, movers and leavers are handled, how privileged access is controlled and monitored, and how access reviews are performed and evidenced.
The emphasis is on decisions the organization can sustain. A review process requiring managers to certify hundreds of entitlements quarterly will be rubber-stamped; one scoped to the access that matters will actually be performed.
Scope
What Heights does
-
Access inventory across critical systems
Who has access to what, at what level, and how each grant was authorized.
-
Joiner, mover and leaver process
How access is provisioned on hire, adjusted on role change, and removed on departure, with the movers step, which is the one most often missing.
-
Privileged access control
How administrative rights are granted, constrained, monitored and periodically re-justified.
-
Authentication standards
Where multi-factor authentication is required, where exceptions exist and why, and what the plan is for closing them.
-
Access review that is actually performed
A review cycle scoped so reviewers can engage with it meaningfully, producing evidence an assessor will accept.
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- ISO 27001
- An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- SOX
- Access, change management and IT operations controls supporting the reliability of financial reporting. Assessed annually as part of internal control over financial reporting.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
How this fits under vCISO leadership
Identity decisions create friction, and friction needs an owner with the standing to hold the line or to grant a considered exception. A vCISO makes those calls and records them, rather than leaving each one to be re-argued.
Where this comes up most
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
Getting started
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
Do we need to buy an identity management platform?
Not necessarily, and not first. Many organizations get most of the available benefit from process and configuration changes in tools they already own.
A platform bought before the process is defined tends to automate the existing confusion. If tooling is genuinely warranted, the strategy makes the requirement clear enough to evaluate options properly.
How often should access be reviewed?
Quarterly for privileged and high-sensitivity access, annually for the broader population, is a common and defensible pattern. Departures and role changes should trigger action immediately rather than waiting for a cycle.
The right frequency is the one that will actually be performed with attention. A demanding cycle that gets rubber-stamped provides evidence without providing assurance.
What about access held by our outside providers?
Provider access should be in the same inventory as employee access, and often deserves more scrutiny, it is frequently privileged, shared between technicians, and outside your joiner-mover-leaver process entirely.
This is a point where identity work and third-party oversight meet, and it is usually handled together.
Related services
- Cloud Security Architecture and Governance Design and governance for cloud environments: what the provider secures, what remains yours, and how you keep track of a platform that changes underneath you.
- Managed Security Services Continuous monitoring, detection and response, and vulnerability management, run against priorities the security strategy has already set.
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.
Talk through Identity and Access Management Strategy with us.
Tell us what prompted the enquiry and what the organization is working toward. You will get a straight view of the right scope, including when that is smaller than you expected.
Or reach us directly at (407) 908-7001 or info@heightscg.com.