How should buyers manage vendor administrator access?

Discussion

Open questionLast verified: 2026-08-13
  • Author
    Posts
  • #3449

    Vendor support staff may need powerful access to troubleshoot a system. What safeguards should a buyer require?

    #3450
    Accepted answer

    Use named accounts, least privilege, approvals for sensitive access, strong authentication, time limits, session logging, and periodic reviews. Separate routine support from emergency access and define how the buyer can inspect access records and revoke access. Shared standing administrator accounts should be rare exceptions with compensating controls. NIST SP 800-207 focuses access decisions on users, assets, and resources rather than on implicit network trust.

  • You must be logged in to reply to this topic.

Reply to this discussion

You must be logged in to reply. Editors verify buy-side questions and cite reviews when answering.

Create an account