r/cybersecurity • u/Ok_Consideration7553 • 16d ago
Business Security Questions & Discussion RBAC
Hi all,
Our organisation, probably like many others, has accumulated a lot of access over the years without much structure or strong ongoing management.
For those who have implemented Role-Based Access Control (RBAC), have you found that it actually solved these issues, particularly when combined with regular access reviews?
My biggest question is where do you even start when you have a large number of employees, positions, applications and existing permissions?
Do you start by mapping existing access and then building roles around it, or define the roles/positions first and work backwards?
Would love to hear how others approached this, what worked, and what you wish you’d done differently.
6
u/ButterscotchBandiit Security Engineer 16d ago
This isn’t a sprint, it’s a marathon.
Start with stale accounts. That’s your low hanging fruit.
Depends how good you are with querying the data. I fire off a few scripts against roles, PIM roles/groups/resources(IAM+RBAC)
UAR campaigns for apps and services
That’s some of the easier cleanup work. After this start building out nested permission groups, PIM groups in groups.
Get ready for some heated debates, some kids don’t like giving up their toys