01

Use individual, limited access

Prefer named accounts, least privilege and time-bound access over shared administrator credentials. Keep approval responsibility with the system owner.

02

Protect the access path

Use an approved credential manager, multi-factor authentication where supported and a defined VPN or network route when required.

03

Close the loop

Record actions, review changes and remove temporary access at the end of the task or engagement.