Услуга · Information security

Protection against unauthorised access

These mechanisms answer a simple question: what a specific person can do on a specific computer. For certified systems they are mandatory; for everyone else they are one of the most underrated protective measures.

Sign-in
a password plus a key
Devices
from the list only
Programs
execution by permission
Changes
under control

What the work includes

The set of mechanisms depends on the goal: certification needs the full complement, practical protection usually needs only part of it.

Discuss the scope

Login confirmation

A password plus a key or a card. The note under the keyboard stops deciding anything.

Devices

Approved drives by list, everything else forbidden, a connection log.

Approved programs

Only what is on the list runs. Ransomware simply does not start on such a machine.

Change monitoring

Watching system files and settings, with an alert on any change.

Rights to resources

Restrictions on folders and devices at the level of the security product, not only of the operating system.

Logs

User actions are recorded, and the records themselves are protected against tampering.

How it goes

We enable the mechanisms one at a time, so that each time it is clear how it affects people work.

01

What is needed

We separate what the regulations require from what we take on for real benefit.

02

Pilot

We install it on several machines from different departments: each has its own set of programs and its own behaviour.

03

Rollout

We roll it out in stages, tuning the rules for each department.

04

Support

We extend the allow-lists and review the blocks.

Keys and cards get lost, and you have to prepare for that in advance. Without a written temporary-access procedure, losing a key means the accountant cannot work for half a day. A backup way in with a limited validity period is thought through at the rollout stage, not in a moment of panic.

Questions and answers

An allow-list of programs. Unlike antivirus it stops not known malware but everything foreign, including what is not yet in any database. The price is discipline: every new program has to be added.

Laptops are configured separately: the same mechanisms plus disk encryption and connection to the work network through a secure tunnel. Turning protection off entirely for a trip is the worst option of all.

The main costs are licences and administrator time to extend the lists. The first month is the busiest; after that the flow of requests drops sharply, because people work with the same set of programs.

We will roll out access protection

Write what needs covering and how many workstations there are. We will propose a set of mechanisms and start with a pilot.