Security & Governance Best Practices

Implement least-privilege design, separation of duties, and periodic access reviews for secure operations

Back to documentation

What you will learn here:

Least-privilege access design

Separation of duties

Periodic access reviews

Account and credential security

Audit logging and monitoring

Change management and documentation

Least-privilege access design

Least-privilege principles minimize security risk by granting only the access required for job functions.

What Is Least Privilege

  • Grant minimum permissions required for tasks
  • Avoid over-provisioning access
  • Use read-only access where write is not needed
  • Restrict administrative access to authorized personnel

Why It Matters

  • Reduces attack surface
  • Limits damage from compromised accounts
  • Supports compliance requirements
  • Prevents accidental destructive actions

Implementation Guidelines

  • Start with minimal permissions and expand as needed
  • Use read permissions for observer/reporting roles
  • Reserve create/modify permissions for operational roles
  • Restrict wildcard (*) permissions to trusted administrators
  • Review and justify all permission grants

Best Practices

  • Document permission requirements for each role
  • Review permissions during role assignment
  • Remove unnecessary permissions promptly
  • Audit permission usage regularly
  • Train administrators on least-privilege principles

Separation of duties

Separation of duties prevents single individuals from having excessive control over critical operations.

What Is Separation of Duties

  • Divide critical functions among multiple people
  • Require multiple approvals for sensitive actions
  • Prevent single-person control over end-to-end processes
  • Reduce insider threat risk

Why It Matters

  • Prevents fraud and abuse
  • Reduces impact of compromised accounts
  • Supports compliance and audit requirements
  • Improves operational oversight

Implementation Guidelines

  • Separate platform administration from tenant administration
  • Divide RBAC management from resource management
  • Require separate roles for create and delete operations where critical
  • Use different accounts for routine and privileged tasks
  • Document separation of duties requirements

Best Practices

  • Define critical operations requiring separation
  • Assign complementary roles to different individuals
  • Review role combinations for conflicts
  • Audit adherence to separation policies
  • Document exceptions with justification

Periodic access reviews

Regular access reviews ensure permissions remain appropriate and aligned with current job functions.

What Are Access Reviews

  • Scheduled reviews of user permissions
  • Validation that access aligns with job functions
  • Identification of excessive or unnecessary permissions
  • Removal of stale or orphaned accounts

Why They Matter

  • Prevent privilege creep over time
  • Identify and remove orphaned accounts
  • Support compliance requirements
  • Maintain least-privilege posture

Review Process

  • Schedule reviews (monthly, quarterly, or annually)
  • Generate list of users and assigned roles
  • Validate each user's access against job function
  • Remove unnecessary permissions
  • Document review findings and actions
  • Track remediation of identified issues

Best Practices

  • Conduct reviews at least quarterly
  • Involve managers in access validation
  • Document review procedures
  • Track and remediate findings promptly
  • Use access reviews to refine role definitions
  • Maintain review records for audit

Account and credential security

Strong account security practices protect against unauthorized access.

Password Requirements

  • Enforce strong password policies
  • Require regular password changes
  • Prevent password reuse
  • Use multi-factor authentication where available

Account Management

  • Disable accounts promptly when users leave
  • Use unique accounts per individual (no shared accounts)
  • Monitor for suspicious login activity
  • Lock accounts after failed login attempts

Session Management

  • Enforce session timeouts
  • Require re-authentication for sensitive operations
  • Log all authentication events
  • Monitor for concurrent sessions from different locations

Best Practices

  • Document account security policies
  • Train users on credential protection
  • Monitor authentication logs regularly
  • Respond promptly to security incidents
  • Review account security controls periodically

Audit logging and monitoring

Comprehensive audit logging supports security monitoring and incident investigation.

What to Log

  • Authentication and authorization events
  • Resource creation, modification, deletion
  • Permission and role changes
  • Failed access attempts
  • Administrative actions

Log Management

  • Retain logs according to compliance requirements
  • Protect logs from tampering
  • Monitor logs for security events
  • Correlate logs across systems
  • Archive logs for long-term retention

Security Monitoring

  • Review logs regularly for anomalies
  • Set up alerts for critical security events
  • Investigate suspicious activity promptly
  • Document security incidents
  • Use logs during incident response

Best Practices

  • Enable comprehensive logging
  • Protect log integrity
  • Review logs regularly
  • Respond to security alerts promptly
  • Maintain log retention policies
  • Include log review in security procedures

Change management and documentation

Structured change management reduces risk and supports operational stability.

Change Control Process

  • Document all planned changes
  • Review changes for security impact
  • Test changes in non-production first
  • Require approval for critical changes
  • Maintain change records for audit

Documentation Requirements

  • Document system configuration
  • Maintain network topology diagrams
  • Record permission assignments
  • Track change history
  • Keep runbooks current

Best Practices

  • Use change management procedures consistently
  • Document changes before implementation
  • Review changes for security implications
  • Maintain accurate documentation
  • Include rollback procedures
  • Conduct post-change reviews

Ready to rethink private cloud?

Lower costs. Simplify operations. Deliver more.