Data access management

Data access management determines who gets access to which data and with what permissions. In companies, rights are typically added as needed and never removed, so that after a while half the people have access to almost everything. The solution is to assign rights by role, not by individual, to apply the principle of least required access, and to review permissions once every period. Employee departures and the end of cooperation with suppliers require particular attention, as forgotten access rights represent the biggest risk. A record of who has access to what also serves as evidence during data protection audits and in the certification of management systems. When deploying corporate AI assistants, this topic is critical, because the tool sees whatever it has access to.

See also: Access policy for company accounts, Company AI assistant, NIS2 and cybersecurity.