troubleshooting Question

innovative way of accounts management (minimal/no creation/deletion of accounts)

Avatar of sunhux
sunhux asked on
OS SecurityAWSSecurity
5 Comments1 Solution18 ViewsLast Modified:
Our IT apps team came up with this idea in our
SaaS AWS OS, applications & DBAs accounts
which they plan to authenticate with Google
MFA authenticator.

As number of staff rarely change (one staff who
leaves will be replaced with only 1 staff) or even
less (say 4 staff leaves, due to cost cutting, will
only replace with 3 staffs), the number of accts
will rarely change/increase.

The idea is:

a) create accounts with names that are generic
    ie doesn't reflect specific IT staff's name.  Eg:
    For DBAs, create dba1, dba2
    For Unix admins,  create ux1, ux2
    For apps admins, app1, ... ,app5

b) each of the above account is assigned to
    only 1 IT staff (ie no sharing of accounts) &
    when a staff leaves, that account's password
    is reset (or possibly disabled) till a new staff
    comes in, the account with the changed
    password is given to the new staff.
    If there's no new staff to replace that position,
    we'll just disable that account.

c) We'll maintain an Excel, so that we know at
    any one time, who is holding which account.
    dba1 > jean   dba2> anna
    ux1>  john     ux2> carl
    app1> ann   app2 > may   app3> joe

    So when Carl leaves & is taken over by a
    new staff  Jon,  the ux2 account will be
    given to Jon.

d) I can't think of any shortfall other than:
 - if we want to know offhand who is the staff
    currently login using an account, we'll have
    to refer to the Excel.
 - in annual accounts review to review if there's
   any dormant accounts to be removed, gut
   feel is there will be lack of visibility from  a
   glance if an account is truly offboarded

e) was told IAM will be used in AWS.  For
   privileged accounts, we plan to lodge the
   credentials into CyberArk SaaS which
   requires approval.

The key question I have is:  will auditors
accept such a set-up/process?  Virtually
the accounts review is just by reviewing
the Excel & not at the OS/DB/apps level.

Any shortfalls anyone can see that audits
will fault us for adopting this?
btanExec Consultant
Log in to continue reading
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform for $9.99/mo
View membership options
Unlock 1 Answer and 5 Comments.
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
The Value of Experts Exchange in My Daily IT Life

Experts Exchange (EE) has become my company's go-to resource to get answers. I've used EE to make decisions, solve problems and even save customers. OutagesIO has been a challenging project and... Keep reading >>


Owner of Outages.IO
Phoenix, Arizona, United States
Member Since 2016
Join a full scale community that combines the best parts of other tools into one platform.
Unlock 1 Answer and 5 Comments.
View membership options
“All of life is about relationships, and EE has made a virtual community a real community. It lifts everyone's boat.”
William Peck

Member since 2004