Permission Creep (also known as Privilege Creep) ranks highly as a cyber threat for any organisation. It typically occurs when staff change roles and nobody bothers to remove their existing access (but read on, as it can materialise in lesser known ways too). It’s also avoidable in almost all cases. The risk of permission creep is significant. A regular user account can become the mother lode for a bad actor or rogue employee. Addressing Permission Creep is also a core component of Zero-Trust Architecture, where we are mandated to leverage the concept of Least Privilege when managing user access.
How Else Can Permission Creep Occur?
- Failure to remove temporary permissions. E.g. Assigning access to someone to retrieve logs from a server as a one-off task but forgetting to remove it.
- The common practice of assigning access to new users based on a departing user. This departing user may have had several roles at your organisation and accrued many unnecessary permissions which the new user will automatically inherit.
- Failure to rescind access to users who complete a secondment to another project.
- Accumulation of access as a user changes between job roles.
- Untracked nesting or inheritance of access through parent groups.
- Failure to rotate service or shared account credentials when personnel leave a team.
- Over-assigning access to ensure a user can do their job (e.g. Providing root access to a server when the user only needs to view log files).
- Trusting the status quo and lack of ownership. E.g. John approved access for Jane when he was manager, I’ll just assume Jane still needs access.
- Service Account permission over-assignment. System implementers may have trouble getting an application to function with limited-rights, and fall back to assigning full-admin rights to remove a blocker. If the service account is compromised, it leaves the organisation with a critical risk.
The Impact of Permission Creep
When excessive permissions are assigned to users and service accounts, the impact can be felt in various ways. Here are just a small handful of potential impacts.
- Regulatory compliance breaches. This can occur if users retain permissions, where separation of duty controls are bypassed or overruled.
- Ease of lateral movement and privilege escalation. If an account is compromised, and it holds more permissions than required, it simplifies the task of attackers to infiltrate systems and capture sensitive data.
- Elevated risk of avoidable service disruptions. The potential for an IT Administrator to make a catastrophic error increases when they are operating with over-privileged accounts. If a job only requires read only access, providing full admin access for the job can lead to unexpected outcomes, it only takes one wrong command or click to suffer heavy repercussions.
- Confidentiality breaches. Staff can unwittingly breach the confidentiality of customers and other staff. When access is not removed, confidential information can unintentionally find its way into reports, extracts and other data stores. This can easily occur in both business and IT functions.
Mitigating the Risk of Permission Creep
Fortunately, tackling Permission Creep is possible using mature Identity Security processes. Implementing Identity Governance properly will allow for regular reviews of user access as well as validation of permissions that are assigned to roles (e.g. Least Privilege).
Automating the lifecycle management such as provisioning and (often overlooked) de-provisioning also significantly reduces risk.
When access needs to be assigned temporarily, it may suit better to apply a Privileged Access Management (PAM) methodology where access is time-boxed to short windows and automatically removed.
Finding and Addressing Permission Creep Risks
Permission Creep is one part of the overall Identity threat matrix that can be applied to any organisation. Identity Synergy+ by Assertiv is a methodology that brings together several key offerings:
- Identity Blueprint for understanding your current Identity landscape which will allow for a clear assessment on how to improve process and close gaps.
- A maturity assessment identifies areas of risk that can be addressed through capability uplift.
- Your Identity Strategy is defined in collaboration with our team to provide a clear business case to drive Identity Security outcomes. Your strategy considers your organisation mission and goals, complexity, priorities, resources and risk.
- Finally your Identity Roadmap clearly articulates the steps necessary to reach your desired security state. It’s tailored for your organisation and includes initiatives, priorities, timelines and resource requirements.
This methodology addresses Permission Creep as well as many other threats to your Identity landscape. If you’re interested in Identity Synergy+, don’t wait until permission creep puts your organization at risk. Contact our team today for an obligation-free consultation and take the first step toward securing your identity landscape.
