Identity and Account Management IAM Controls

What is it?

Identity and account controls govern who can access which resources within an organisation’s environment. By defining roles, permissions, and proper authentication methods, these controls ensure that legitimate users have the access they need—while keeping unauthorised individuals out. Good identity management reduces risk, supports compliance, and enables smooth business operations.


What could happen?

If identity and account controls are weak, attackers can exploit orphaned accounts, default credentials, or excessive privileges. This can lead to data breaches, privilege escalation attacks, and compromised business processes. The result is often financial loss, reputational damage, and potential legal complications.


What to do about it?

Foundational: Introduce a standard account request and termination process, ensuring prompt removal of access for departing employees.
Outcome: Minimises the risk of outdated, vulnerable accounts remaining active.

Enhanced: Deploy identity management solutions (e.g., Azure AD or Okta) to centralise user provisioning, enforce strong authentication, and implement role-based access control (RBAC).
Outcome: Streamlines account management and enforces consistent, organisation-wide controls.

Comprehensive: Integrate identity governance solutions to continuously audit and review user permissions, applying the principle of least privilege dynamically. Link these solutions to HR and access request workflows to ensure ongoing accuracy.
Outcome: Ensures a proactive, real-time approach to identity security, reducing the window of opportunity for attackers.