Policy
[Company] grants access to systems and data holding Specified Information on the basis of role and need. Access is assigned to groups, never to individual accounts. A group with one member is still a group. The owner of the company holds no enclave access unless the owner's role requires it.
Account types allowed: individual user, individual privileged (separate account), service. Account types prohibited on enclave systems: shared, guest, anonymous, temporary without an end date.
Privileged accounts are separate from daily-use accounts and are used only from a dedicated administration workstation with no email or web browsing. Privileged actions are logged.
Accounts are disabled the same day a person leaves or changes roles, after [30] days of inactivity, or when HR reports a significant risk. Account managers are notified within [1 business day] of any of those events. Users log out after [8 hours] of expected inactivity or when leaving the site.
Group hierarchy
ENCLAVE-USERS membership = screening complete, training signed
PROJ-[A]-ENGINEERING drawings, BOMs (read/write)
PROJ-[A]-FIRMWARE source, build artifacts (read/write)
PROJ-[A]-QUALITY test records (read/write); drawings (read only)
PROJ-[A]-MASTER everything in the project; [2] named people
ENCLAVE-ADMINS separate admin accounts only
BUSINESS-USERS office network; no enclave rightsReview
Group membership is exported and compared to the HR active list every [quarter] by [owner, role]. The export and the review record are retained as evidence.
Owner: [name, role]. Reviewed: [date]. Next review: [date].