Skip to content

Cybersecurity planning

Ask who owns vendor access before a project starts

Outside specialists may need approved access to help deliver or support a system.

Outside specialists may need approved access to help deliver or support a system. Establishing ownership at kickoff makes that access easier to review when the project changes or ends.

Define the purpose and owner

Record the business reason for access, the systems involved, and the internal owner who approves it. Ask the responsible security and technical teams to determine the appropriate access method and permissions. Avoid treating a vendor's participation in the project as a blanket approval for every connected system.

Plan the working period

Identify when the access is needed and who coordinates activities during that period. Keep the vendor contact, internal coordinator, and escalation path together. Use the organization's approved process for credentials and sensitive connection information instead of including them in a shared project schedule.

Include the end of the engagement

Assign responsibility for reviewing access when work is complete, personnel change, or support arrangements end. Record which continuing permissions have an approved business purpose. Confirm the status through the designated access-management process so an expired project does not remain the only explanation for ongoing access.

Practical takeaway

Vendor access should have a purpose, an internal owner, and a review point. Those basic records help connect a project relationship to the organization's established security controls.

Related services

Further reading