Data protection
Access management and authorisation
We make it visible who can reach what, collect excess permissions and tie the arrangement to a review cycle.
- ISO/IEC 27001
- KVKK m.12
Access rights are the most concrete form of the technical measure KVKK art. 12 expects. They are also where most audit findings come from: the leaver's open account, the role changer's old permissions, the shared administrator password.
Scope
Producing the account and permission inventory
Role design and applying segregation of duties
Setting up single sign-on and multi-factor authentication
Moving privileged accounts into a vault
A periodic access review calendar
What we deliver
A current permission matrix
Role and policy definitions
SSO and MFA in production
Review procedure and calendar
The process for this service
Inventory
Which account exists in which system with which role; orphaned accounts are listed separately.
Role design
Roles are modelled on job definitions and segregation of duties applied.
Rollout
Single sign-on and multi-factor authentication go live; privileged accounts move into a vault.
Review
A periodic approval cycle goes on the calendar; unapproved permissions are removed.
Questions about this service
Our products supporting this service
Other services in the same pillar
See where you stand in 20 minutes
The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.
Look at it yourself first
A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.
Start the compliance testLet's look together
We discuss your current state and work out which step comes first and how long it takes.
Request a conversation
