Skip to content
HEM Bilişim
All services

Access management and authorisation

We make it visible who can reach what, collect excess permissions and tie the arrangement to a review cycle.

  • ISO/IEC 27001
  • KVKK m.12

Access rights are the most concrete form of the technical measure KVKK art. 12 expects. They are also where most audit findings come from: the leaver's open account, the role changer's old permissions, the shared administrator password.

Scope

01

Producing the account and permission inventory

02

Role design and applying segregation of duties

03

Setting up single sign-on and multi-factor authentication

04

Moving privileged accounts into a vault

05

A periodic access review calendar

What we deliver

A current permission matrix

Role and policy definitions

SSO and MFA in production

Review procedure and calendar

How we proceed

The process for this service

1

Inventory

Which account exists in which system with which role; orphaned accounts are listed separately.

2

Role design

Roles are modelled on job definitions and segregation of duties applied.

3

Rollout

Single sign-on and multi-factor authentication go live; privileged accounts move into a vault.

4

Review

A periodic approval cycle goes on the calendar; unapproved permissions are removed.

Questions about this service

See where you stand in 20 minutes

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation