ministryofjustice / itpolicycontent

Draft and review content for MoJ IT Policy.
10 stars 14 forks source link

Shared account guidance #61

Open warmanaMOJ opened 5 years ago

warmanaMOJ commented 5 years ago

In some cases, a shared account might be appropriate or even essential, rather than a personal (individual) account.

This issue is to provide best practices and guidance for determining when a shared account is appropriate, and how it should be used and managed.

cybersquirrel commented 5 years ago

I'm intrigued as to when it would be essential...

warmanaMOJ commented 5 years ago

@cybersquirrel In a work scenario, presumably not often. Perhaps because of a limited number of accounts available during a service evaluation? Admittedly, 'essential' rather implies a mission-criticality which would simultaneously make non-shared accounts increasingly preferable. Replace 'essential' with 'unavoidable'?

cybersquirrel commented 5 years ago

I suspected that was what was in-mind. I suppose it also depend on what we mean by 'shared' - is it shared in terms of multiple-people-to-single-account, or single-account-across-multiple-purposes (e.g. using a Google account for personal and work stuff).

warmanaMOJ commented 5 years ago

@cybersquirrel As posed, it was the former, but definitely the latter is an important scenario to address, too.