Skip to content
Standing Access

Contents

Everything here, in eight sections. If you are scoping a programme, read the foundations and then discovery. If a deployment has stalled, start with the note on how these programmes fail.

Foundations

6 notes

Three separate problems get sold as one product. Plus the condition every other control works around: administrative rights that are permanent, and the tiering rule that closes the most paths.

Finding what exists

6 notes

Every organisation finds several times more than it expected. The account list is the beginning; what matters is who can become an administrator, which is a graph rather than a list.

Credentials

7 notes

Storage, rotation and the dependency mapping that blocks it. Plus the route around the control for when the control itself fails, which will otherwise be invented under pressure and never documented.

Access models

7 notes

Removing standing rights is the intervention with the largest effect and the most resistance. Plus the gap most deployments leave open: the device the administrator is sitting at.

Session recording

7 notes

Recording is workplace monitoring with obligations attached, and it is evidentiary rather than preventive. Both are stated plainly here, because deployments that overstate it fail at the first incident.

Running it

7 notes

A broker that is down stops all administrative work, including fixing the outage. Plus why administrators route around deployments, which is usually a design finding rather than a discipline problem.

The programme

6 notes

The order determines whether value arrives in months or never. Plus the reporting discipline that separates a working programme from one measuring its own activity.

Reference

4 notes

What this defends against and what it does not, why the insider framing is both overstated and damaging, and the residual risk list that makes every coverage claim believable.