Skip to main content
Guidance

10 Steps to Cyber Security

Guidance on how organisations can protect themselves in cyberspace.

Page 7 of 11

Identity and access management

Control who and what can access your systems and data.

Access to data, systems and services need to be protected. Understanding who or what needs access, and under what conditions, is just as important as knowing who needs to be kept out. You must choose appropriate methods to establish and prove the identity of users, devices, or systems, with enough confidence to make access control decisions. A good approach to identity and access management will make it hard for attackers to pretend they are legitimate, whilst keeping it as simple as possible for legitimate users to access what they need.




Published

Publish date

Reviewed

Version

1.0

Written for

Written for