[Verse 1] Sarah needs the data, but can she get inside? First we check her identity, then we'll decide Authentication proves she's really who she claims Multi-factor verification, playing security games Username, password, plus her phone's one-time code Three factors together unlock the access road [Chorus] Who gets in, what they see, when they're allowed to stay RBAC and ABAC showing us the way Least privilege, need to know, keep the access tight PAM for privileged users, monitor day and night Access control, access control, guarding every door Access control, access control, that's what we secure for [Verse 2] Roles define the boundaries, attributes refine Marketing sees campaigns, finance sees the bottom line Account lifecycle spinning from provision to delete Regular reviews ensure no access stays obsolete Service accounts inventoried, owners clearly named Quarterly audits verify that nothing's been unclaimed [Chorus] Who gets in, what they see, when they're allowed to stay RBAC and ABAC showing us the way Least privilege, need to know, keep the access tight PAM for privileged users, monitor day and night Access control, access control, guarding every door Access control, access control, that's what we secure for [Bridge] Sessions timeout when you're gone Remote access, VPN strong Policies state the overarching rule Standards specify each tool Procedures detail every step we take Two business days to make no mistake [Verse 3] Identity management from cradle to the grave Provisioning new users with the access that they crave But only what they need to do their job and nothing more Deprovisioning when they leave, lock and bolt that door Authentication commensurate with sensitivity's call Higher risk means stronger gates protecting it all [Final Chorus] Who gets in, what they see, when they're allowed to stay RBAC and ABAC showing us the way Least privilege, need to know, keep the access tight PAM for privileged users, monitor day and night Access control, access control, guarding every door Access control, access control, keeping data secure [Outro] From request form to provision Following our access mission Who can interact, which resources, what conditions Access control, our security ambitions
← 3 Classification by Implementation Layer | 2 Change Management →