Skip to content
English
  • There are no suggestions because the search field is empty.

Secure Regulation of Access to IT Systems, Data and Applications at Eye-Able

How does Eye-Able ensure that access to IT systems, data and applications is securely regulated?

This article gives an overview of Eye-Able's identity and access management and the measures used to regulate access according to the need-to-know principle – particularly for privileged access.


Identity and Access Management System (IAM)

Eye-Able operates a comprehensive identity and access management system (IAM) that governs policies, procedures and technical controls for granting, changing, revoking and monitoring user rights.


Least privilege principle and separation of duties

Access rights are granted according to the least privilege principle and in compliance with the separation of duties principle.


Central authorisation management

The initial and ongoing granting of rights is carried out through a centrally documented authorisation management with defined approval paths.

Access for new, changing or departing users is adjusted promptly.


Privileged access and MFA

Privileged access is kept to a minimum, time-limited and subject to separate approval and logging obligations.

MFA (multi-factor authentication) is mandatory for all administrative and sensitive access.


Password policy and logging systems

The password policy meets standard industry security standards (including minimum length, rotation, complexity) and is reviewed regularly.

Logging systems are configured as write-once/read-many (WORM); their "read-only" status can only be temporarily lifted through controlled break-glass procedures.


User identities and regular review

All user identities are uniquely attributable and documented.

Access rights are reviewed regularly in accordance with a risk-based revalidation plan.


Further help

Do you have further questions or need personal support? The following article explains how you can get in touch with us: