shared accounts security risk

The natural flow of business means employees move around within the organization. The website does not have anything to do with the health industry and no financial information will be tracked in it. SANS publish a white paper on the issues of shared accounts which may be useful if you need to quote something published to support your claims. The fact that you do not understand why they are asking you this question is interesting to me. Information Security Stack Exchange is a question and answer site for information security professionals. Re-Sharing Shared Credentials: Under GDPR, is one user borrowing another's logged-in session for financial transactions illegal? When you create a company policy, it is much easier to enforce "NEVER EVER share accounts", than "well, you should never share an account, but in some cases, like a read only account to not-so-secret information for a limited period between two people that work together, you might do that, if the real risk … Many IT organizations use shared accounts for privileged users, administrators or applications so that they can have the access they need to do their jobs. If managed incorrectly though, this practice presents significant security and compliance risks from intentional, accidental or indirect misuse of shared privileges. The challenges shared accounts hold for IT: Activity Tracking and visibility: Then because of accountability, security encouraged to have individual accounts sharing roles. Regardless of the reason, shared accounts present a host of security risks to the network. They switch departments or leave the company. For an organization to change credentials every time a user with shared-account access leaves or switches departments is not only unscalable, but it's also impractical, and leaves a lot of room for human error. While shared accounts are not considered best practice, an organization may end up using shared accounts for a variety of reasons. As you are exploring right tools to reduce the risk with shared accounts and privilege management think about the following: To control costs, plan ahead for evolving requirements. Several users and some of the business stakeholders are asking that we support and encourage shared logins to one of our new websites.

