Услуга · Information security

Application protection

From outside the accounting system is usually closed, while inside it is wide open: an ordinary user sees far more than their job requires, and the integrations run under a full-rights account because that was easier to set up. That is what we put in order.

Roles
by duties
Integrations
an account of its own for each
Log
who changed what
Testing
on the weak points

What the work includes

We treat applications not as programs but as stores of your data and as channels through which that data leaves.

Discuss the scope

Roles

Rights by role instead of full access. A salesperson has no need to be able to export the entire client base at once.

Integration accounts

Every integration has its own account with the minimum rights required, not a shared administrator.

Programming interfaces

Restrictions by address and key, and a rate limit on requests.

Action logging

Who changed it, who exported it. Without that there is simply nothing to investigate with.

Updates

A procedure for installing security fixes with mandatory testing on a test environment.

Finding weak points

Testing applications and reviewing the findings in order of importance.

How it goes

The main difficulty here is not technical: the hardest part is agreeing who genuinely needs to see what.

01

Inventory

Which applications are used, by whom, what data is inside and where it is sent.

02

Matrix

Together with the heads of departments we define the roles and what goes into them.

03

Configuration

We introduce roles, move integrations onto separate accounts and switch on logging.

04

Audit

Every six months we reconcile rights against job roles: people move on and their access trails after them.

An integration running under an administrator account is a gift to an attacker. Finding the password in the exchange configuration file is enough to gain full access to the accounting system. A separate account with rights only to the operations needed costs half an hour of configuration.

Questions and answers

Through the heads of departments, not through the administrator. Only they know what their people need for their work. Two or three meetings are usually enough, and the outcome is written up as a table that can be maintained afterwards.

Disable on the day of departure rather than deleting straight away: a deleted account takes the history of actions with it. Disabling and reviewing a month later is a safer scheme than immediate deletion.

Whoever administers them, but to a written procedure with deadlines. Otherwise updates are postponed indefinitely: it works, after all. That is exactly how holes survive for years.

We will put rights in order

Write which systems you use. We will see who sees what and where the integrations run with excessive rights.