Skip to content
Amrani Academy

4. User access control and certification

User access control

Access to accounts and administrative privileges should be tightly controlled and regularly reviewed.

What this requires

  • Every user has their own unique account, no shared logins.
  • A defined approval process before a new account is created.
  • Administrative privileges are only given to people who genuinely need them to do their job, and only used for tasks that require them, not for everyday email and browsing.
  • Multi-factor authentication is required for cloud services, and for any account with administrative access, this became a mandatory requirement in the 2022 update to the scheme.
  • Accounts for people who've left, or who no longer need access, are removed or disabled promptly rather than left dormant.

Dormant accounts and over-privileged everyday accounts are two of the most common findings in Cyber Essentials assessments, and both are straightforward to fix once you know to look for them.

Course contents