EricBrooksGhost
Well-Known Member
- Joined
- 19 Oct 2010
- Messages
- 2,739
Password protection on its own is archaic. Any organisation serious about IT security will have VPNs all over, and every employee will have a physical token, bit like a USB stick. No token, no access, go home. Lose your token it gets disabled for ever, you have to beg IT for a replacement. When an employee leaves the company access via their token is auto disabled, the employee should hand it on last day, but even if they don't the token is disabled for ever. Also on the last day of employment all passwords should be disabled for ever. Allowing the dippers access to our scouting network after they left was just negligence by us.
Never said you don't remove creds/disable access to people who leave so not sure what the point is.
Also I don't disagree on password only based access.I said if they used an existing user's credentials removing the creds of the person who left may be irrelevant because we don't know technically how the system was accessed such as VPN or another approach. We don't know enough about the system in question e.g. was it SaaS based run by a 3rd party accessible from anywhere? So we should avoid assumptions.