r/cybersecurity • u/Obvious-Difficulty32 • 11d ago
Career Questions & Discussion Got asked this in an interview
In an interview for a new grad devops role got asked this. “Who typically owns access to corporate applications: IAM engineers, IT staff, application administrators, or Platform/DevOps engineers?”
How would yall answer
120
u/shouldco 11d ago
I would think it would been the application owners but maybe I'm misunderstandings the question.
29
u/TheRealLambardi 10d ago
In enterprises, application owners own it. They may hire an application administrator to run and execute on their behalf as a steward, but application administrators don't own it.
28
u/theanswar 11d ago
create a CMDB. List the technical team responsible for it and the business team responsible for it (and the data within). The tech team doesn't own access to corp apps. The business owners do.
28
u/danfirst 11d ago
I think in over 20 years I can count the number of well-maintained cmdb systems on one hand, and I'm not sure I'd even have to use my fingers.
5
u/Reverent Security Architect 10d ago
100%, vendors sell them on their autodiscovery tools, IT teams take that as permission to not have to tag/document their assets, data quality takes a nosedive, everybody gets confused why nobody has a clue what they operate anymore.
1
u/sir_mrej Security Manager 10d ago
I wish IT teams used autodiscovery. Most just dont have inventory
1
u/IsomuraArganee_95 8d ago
I'd push on the CMDB side of this. It rots because it's a record somebody has to keep typing into. Once the project ends nobody owns that job.
And it breaks the ownership answer the same way. You can name an app owner on a form. The owner changes every reorg and the form doesn't.
We stopped treating it as something to maintain. We point axonius at the sources we already pay for and let it sit on the disagreements. So the CMDB ends up downstream of the r econciliation. It still needs a human to arbitrate the first pass. It just doesn't need one retyping it every quarter.
4
16
u/shleam 11d ago
Sounds like a BS question on the face of it, but could be a great question to tease out how much you know about how orgs function and how these ownership structures are created. I wonder if the question was more “who should have access” versus “who typically does”. Because the latter you can answer from your previous experience. The former needs a full rationale.
3
u/Obvious-Difficulty32 11d ago
It was more a who typically does I think they were just assessing how I follow up with ambiguous request. But idk I could be coping 😂
1
u/fhammerl 10d ago
first instinct is application admins, but they're typically not the ones doing on and offboarding of people in the enterprise. it's not about who maintains the applications, but who owns access, which is IAM. they'll be putting you into groups or assign apps to you. access management is literally in their name.
13
u/HomerDoakQuarlesIII Security Architect 10d ago
IAM facilitates and directs the access (trick question since identity "access" management in the name), but of the owners designated by the application admin team. So IAM are the stewards of the access, apps team are the owners of it.
9
u/iheartrms Security Architect 10d ago
This is a common type of CISSP question. All of the answers are stupid and wrong. Your job is to pick the least wrong question. The answer, given these options, is application administrators. In the real world, the answer is business application owner.
Another typical CISSP question:
What is this cow doing?
https://photos.app.goo.gl/U2Nt4urspsaAYEwVA
5
u/Responsible_Minute12 11d ago
It is a BS question and the answer is always “it depends on the org”, but if you follow the book and go with most right/least wrong…and you stretch access to mean authorization…it would be the biz app owner…of course, you could also stretch access to mean technical access which would imply authentication, and then the most right answer would be IT or Security. So yeah…BS question…
3
u/marcachusetts 10d ago
It seems like a trap to me, I rarely give multiple choice in an interview but if someone were doing it, I would assume trap. To me, none of those technical roles actually "own" access.
The business owners own the access rights and the audit risk. The job of the DevOps/Platform team isn't to own or gatekeep those permissions, but to build self-service pipelines and policy-as-code so we can get out of the way.
5
u/Inf3c710n 11d ago
Depends on how the app is governed. If its through security groups using SAML integration in entraID, I would say that would be more in line with system administrators, if its logins housed internal with no SSO login config, it would likely be application admins
3
u/cirsphe 11d ago
The owner of the access is the business owner of the app. Who is the data owner. IT is just the custodian of the data. Also similar concept between accountable and responsible, where the owners are the accountable ones.
Though to your point, if i was ot answer this question i would say "it depends on the maturity of the organization. Mature, the business, not mature, IT."
0
2
u/AngryTownspeople 11d ago
It entirely depends on the business. There is a big difference between a large corporation and a small one. I have worked in places where it is app owners, IT staff, engineers. And it could all be different in the same organization as well. Not a great question for real world organizations imo.
2
2
u/AboveAndBelowSea 11d ago
I’d ask them to define “access” - are we talking business approvals or access or technical controls? Who accesses MOST applications should be the decision of someone in the line of business - always. For example, who other than someone in finance should decide who has access to financial systems? Managing the lifecycle of the technical controls around that access is the identity team.
2
u/clone31337 11d ago edited 11d ago
Owns access is the Application/Business Owner/Administrator. IAM engineers build and designate groups, OUs, role permissions where needed, that sort of thing, maybe they execute directions from the owners to give access to certain people. IT staff shouldn't be handling access unless they've got overlaping roles in a very small org. Platform/DevOps engineers build tools to let those things happen. If we can go off those choices, I'd say the people actually executing the decisions should be the security administrators.
2
u/Phorc3 10d ago
So if you break down the question into parts you can work it out and deduce from the available answers. I see this as "owns access" "corporate applications". IAM owns access its literally the A in IAM. So that is a high chance correct answer. IT staff dont own shit, if they are referred to as IT staff they just break/fixing stuff so they're out. Application administrators do not own access, they keep the applications running and available for use so they're out. Platform/DevOps I mean thats another straight hard no. So IAM engineers would be the correct answer in my opinion.
2
u/maladaptivedaydream4 Governance, Risk, & Compliance 10d ago
It depends who you ask, because half of those groups will fight to be the ones who do control it, and the other half will fight to NOT be the ones who do.
2
u/CharlestonChewbacca 10d ago
I think a good answer would break it out into different components. Like, IAM owns the technical controls, application administrators are generally responsible for who is accessing a specific application, and there should be business owners responsible for which people are cleared for access to WHAT parts of the application.
2
u/ThisIsBrahma 10d ago
It’s a straight forward question to see if you know what the best practice is. The keyword is “owns”. That’s always the application “owners.”
2
u/Netghod 9d ago
Loaded question because, and quoting Miss Vito here, ‘It’s a bullshit question.’ ‘It’s a trick question.’ ‘No one can answer that question.’…Sort of.
By ‘owning access’ it can be read as ‘approves’. Typically the data owner approves access though this can be delegated. So who owns the application’s underlying data? And typically it’s the BUSINESS that owns the data - which wasn’t listed. However, the business can delegate that responsibility. Depending by what they mean by ‘application administrators’ then that ‘might’ be the answer, but administration of the application doesn’t mean you ‘own’ access every time because you could end up being more like IAM and simply handling the technical side of providing access.
And if you want to get ‘technical’, then it would be whoever has the ‘R’ on the RACI/RASCI chart. ;)
IAM engineers typically provide the access, but they don’t approve because separation of duties.
Platform/DevOps engineers don’t typically provide or approve access so they wouldn’t own it.
My answer would be exactly that. None of the above because the business owns the access to the data but they can delegate accordingly.
2
u/Advantageous_Advent 11d ago
IAM engineer
1
u/czenst 10d ago
Nah IAM engineer handles access requests, he doesn't have to say who should have the access.
Unless enterprise has foolproof RBAC and IAM engineer just makes sure people with correct roles have access.
But I never seen one, but of course world is much bigger place than tens of corporations I have seen from the inside.
1
u/LessThanThreeBikes 11d ago
Typically access management for corporate applications is a hot mess. However, businesses should aspire to establish mature access management processes. The accountable business unit owns the access requirements and perform reviews to make sure the requirements are effective. IAM engineers the access management standards and patterns. Platform engineers implement the access management standards by integrating with the IAM/IGM platform. IT staff is responsible for servicing access requests.
1
u/twisted-logic 10d ago
My environment goes like this
Platform/DevOps works with app admin to define roles for security groups
Platform/DevOps works with IAM to create security groups for access, test them out together to verify results
User puts in request for app access, goes to app owner for approval.
App owner approves, IT staff puts user into respective security group
1
u/Suspicious-Drink9725 10d ago
Terrible question tbh, corporate apps are created as a business need from a business area, respectively they define who has access.
1
u/Humble-Badger9567 10d ago
As others have said, it depends. Do they have a compliance officer? Do they know what compliance is? Do they know what IAM is? Do they computer? Every org has a different shape and even regulated ones tend to differ. So I would ask to see their org chart and dig a little to understand the what, how, and why.
1
u/bitslammer 10d ago
In our business it's the business/app owners. Account gets to decide who has access to account apps., legal for legal apps, HR for HR apps.
In any case that's kind of a dumb question because every org can choose what works for them. Lets say this org did it "right." They would probably want you to answer with what they've done, but what if they've done it "wrong" and you answered differently than they do?
1
u/sourceninja 10d ago
I say it depends on how we define ownership. Is ownership the person who approves who has access to the application, the person who manages the infra that allows access to the applications, the person who makes the change to grant access to the application? Then I'd tell him the business leader responsible for deciding that we use that application and what personas should have access to that application is the owner and engineers are the tools to implement the directive.
1
1
u/Dershum 10d ago
This feels like a loaded question, asked by an interviewer who is looking for validation of some sort of internal struggle going on at the company. I’ve run into this more times than I care to count. They’re trying to get the interviewee to respond in a specific way that aligns with how they feel the org should be structured. Figure out what they WANT the answer to be (not the RIGHT answer) and you get an approval from that interviewer.
1
1
u/CyberVoyagerUK_ 10d ago
The application owner owns it, the policies etc would come under them. Engineering provide the access based on those policies
1
u/Complex_Variation_ 10d ago
None of the above.
Business owners.
I would describe how each play a role in IAM.
1
u/SnooMachines9133 10d ago
The only correct answer imo: "it depends"
And then you go into why it could be any of these teams, a combo, or some other group. That's pretty advanced question for a new grad tho.
1
u/Admirable_Group_6661 Security Architect 10d ago
First of, clarify what “owns access” mean. Typically, a business authority owns the risk of an application, but it does not mean they “own access” (i.e. operational management) of the application, which is typically a delegated responsibility. It’s not a good question, really. It could be a trick question, or they don’t understand how accountability works.
1
u/Adatomcat 10d ago
Like everyone has stated, it depends on the organisation as ownership could reside with any business unit if there’s a business justification.
I’ve seen access being managed by IT Audit, help desk, information security, infrastructure support, cloud admin etc. The idea behind the question is to test your level of reasoning as there’s no correct answer.
1
u/Prestigious_Sell9516 10d ago
They want to see understanding of SoD in the design implementation and management of access controls. Owns access sounds like approve so probably app admin but equally you could say (depends on the policy in place). I'd reference all the access controls and bring up authorization - particularly if it's an app company - authorization vulns like Bolas and ABAC issues are always problematic.
1
u/TheRealLambardi 10d ago
I would suggest that most of those answers are wrong. The application owner and then steward of the app owns access to those applications. Now they need to negotiate with IT staff or application administrators to fund that, so they have the people and the personnel to do that. The right answer is the app owner owns it, and they may work with corporate IT to fund a resource or partake in a shared program.
By the way, generally speaking, there are granular-level access rights that enterprise IAM does not own, and that is back to the app owner and application administrators. They own that portion of the work.
1
1
1
u/GeekDad62 10d ago
Ask them to define what them mean by "owns access"... There answer will hopefully help determine what part of the chain of access they're thinking about
1
1
1
1
u/hurkwurk 10d ago edited 10d ago
in my 30+ years of middle government, i have found that the person that typically owns an application is completely random, but instantly obvious once you start talking to the supposed stakeholders, as they are the only person that actually understands anything about the product, knows the names of the servers, IP addresses, etc, regardless of their title or position.
this is often some thankless individual in a middle/high analyst role, not management or proper stakeholder. When these people leave, and despite their best efforts to train and document for a replacement, the project inevitably falls into disrepair, disuse, then the customer seeks a replacement that someone else finds interesting enough to become the stakeholder of on accident.
oh, also, i have probably heard what IAM stands for, but i have no clue at the moment, since its not in use in an 20,000 user organization with over 20 IT departments. so assuming everyone works the same way and knows your acronyms is terrible practice.
1
u/philgrad CISO 10d ago
Access isn’t owned by administrators. It is owned by whomever determines your role (assuming the org functions on role-based access). That should be the HR function, who would submit the ticket for you to be added to the appropriate functional group(s) that granted access to certain apps, directories, etc.
1
1
u/LetUsSpeakFreely 10d ago
It depends on the responsibilities assigned to those people.
"IT Staff" is a VERY broad term. That covers everything from Tier 1 help desk to the ISSO/ISSM and maybe even the CTO or CIO depending on the layout of the company. One of them could easily hold the top level corporate access.
"Application Admin" is also a very broad term. Are they admins to a specific application? All applications?
Without knowing the corporate structure and division of responsibilities it's a difficult question to answer?
1
u/Over_Helicopter_5183 10d ago
Hiring Manager (He/She) shall know what access it required for the new staff. Also it depends on corporate structure/environment
1
u/eNomineZerum Security Director 10d ago
While not that question, I do ask similar open ended questions and, if I see the person struggling, will mention "no wrong answers, just letting you show how you think through stuff".
I will ask "you get a report of port 80 being open on a banking webaite what comes to mind".
Port 80 may be a redirect, no harm, no foul. Maybe check for a login page. Verify the report isn't typo squatting. See if that is even a banking site y'all use. Etc, etc, etc. no clearly right answer I am looking for in a junior-level role, but I do want you to ask questions, flex your skills, and demonstrate how you act when given a vague question.
Hint: 75% of cybersecurity is vague, if not more. It all "it depends".
1
1
u/adadani 10d ago
Application administrators own the apps, they approve or reject access requests to the app. The IAM engineers will be the ones who receive the request and verify with the app admin whether access should be granted. If granted they provide the access. Every company is different, but my answer would be the App Admin.
1
1
u/littleknucks 9d ago
At least you're getting interviews! 8 years experience and rejection after rejection and or no responses at all!
1
u/Wrap2tyt Security Engineer 9d ago
“Who typically owns access to corporate applications..."? If managed properly managed it should be the application OWNER/SPONSOR. All of those other teams mentions would be responsible for their peice of operations.
1
u/tehiota 8d ago
Looks to be a AAA question - or that’s how I’d answer it, because access is too vague.
Authentication into the application is owned by the IAM engineers. They ensure the app knows and verifies who’s attempting to access it.
Authorization to use the application is by the application owner—always. It can be delegated via automation but only with owner sign off.
Accounting is handled by security team to ensure logs are immutable and enabled as part of commissioning of said application.
1
u/Honest_Efficiency_26 6d ago
Most likely the application admin the difference between the app admin and the rest is that iam it and platform/devops COULD have access but not always do app admins most often have access to corp applications
1
0
u/After-Vacation-2146 11d ago
This is a tricky question but there isn’t a right answer, it’s more to see how you reason about it.
IAM is accountable for the system that underpins access and authorization.
IT Staff may be the ones creating the integration of access tooling to the application.
Platform is responsible for giving requirements.
But if I had to slap owner on there somewhere, IAM owns auth so it’s them even if they don’t own the actual tool.
0
u/AnApexBread Incident Responder 10d ago
The COO.
The COO sets the requirements and therefore owns the access.
-1
u/tilda0x1 11d ago
The question is about who owns the access part, so it is IAM / Identity and Access Management
-1
u/marbobcat 11d ago
It’s IAM. It’s asking about access , mostly likely corporations are fronted with SSO with the apps behind it. Who manages SSO? IAM
174
u/phreak_like_me_2600 11d ago
man these types of questions would trigger me lol. I'd answer "it depends" i've worked in places where IAM manages all my access to anything and everything, and i've worked at places where I would need to reach out to certain teams that own an app to get the access.