Cybersecurity Glossary

Identity and Access Management

The practice of controlling who exists in your systems and what each person may reach.

What Identity and Access Management means

Identity and access management covers the whole life cycle: creating an account when someone joins, adjusting it when they change role, and removing it when they leave. It also covers how access is granted, reviewed and revoked, and how exceptions are recorded.

Why Identity and Access Management matters for small businesses and nonprofits

Most small organisations have grown their access arrangements by accident. The result is people holding rights from a previous role, dormant accounts nobody owns, and no reliable answer to the question of who can see the payroll file.

What to do about Identity and Access Management

Three steps to deal with Identity and Access Management

  • Produce a list of every account and its owner, then remove what has no owner
  • Make joining, changing role and leaving a defined checklist with a named owner
  • Review who holds administrative rights at least twice a year

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.