Local council systems and data stores contain a vast amount of confidential information on data subjects who live within a borough or county. This presents local authorities with a considerable responsibility to protect the members of its community and the data it retains on them.

When securing any data, managing access to information is key. In the following sections, we’ll look at two different types of privilege access management that may be useful to local councils.

Just-in-time admin

A systems administrator will traditionally use credentials to access a dedicated admin interface. Possessing these credentials relates the user with a set of high-privilege functions. A system then accepts this relationship, allowing the systems admin to perform high-privileged tasks.

The problem arises when an attacker steals such credentials, as this gives them high-privilege access. An attacker that is able to use these credentials can cause substantial harm to a system and the data it contains.

“Just-in-time” administration can help. Rather than inputting credentials and receiving immediate access to an admin interface, it creates a request for access instead. When a request is granted to access high-privilege areas, credentials are only issued temporarily to a systems administrator.

Just enough admin

An administrator’s credentials often grant exceptionally high-level permissions, with access often described as a ‘superuser’, ‘root’ or simply ‘administrator’ level. Unfortunately, if an attacker obtains this level of access, they can cause a range of harmful actions, accessing, stealing or deleting data, or even turning off critical systems.

These credentials allow admins to perform any activity on the system, but in truth, they rarely need complete access. Instead, access should only be given to system areas and data essential to a specific task to limit risk.

“Just enough” administration is another name for the concept known as “least privilege”. In this approach, admin roles are predefined, and access is granted only to parts of the system required for a particular function to be performed.

