Access Management Policy
About This Document
This policy defines how 7 Minute Security LLC manages access to its systems, tools, and client environments. It covers all personnel, subcontractors, and the platforms they use.
1. Purpose
Access to systems, data, and client environments is one of the highest-risk areas for a cybersecurity services firm. This policy defines how 7MinSec grants, manages, monitors, and revokes access, ensuring that only the right people have access to the right resources at the right time.
2. Scope
This policy applies to all 7MinSec personnel and subcontractors accessing 7MinSec internal systems (productivity suite, file storage, report authoring platform, password manager, etc.), client networks and systems during authorized engagements, and any cloud services or SaaS tools used in the delivery of 7MinSec services.
3. Guiding Principles
4. Authentication Requirements
4.1 Passwords
- All 7MinSec personnel and subcontractors must use the company-designated enterprise password manager
- All passwords must be unique, randomly generated, and never reused across accounts
- Passwords are a minimum of 12 characters where the account is protected by multi-factor authentication, and a minimum of 16 characters where multi-factor authentication cannot be enabled on the account
- Passwords are generated by the password manager using its full character set, covering upper case, lower case, numeric, and special characters. Where a password must be typed from memory, such as a device login or the password manager's own master password, it is a passphrase of at least 16 characters
- Passwords must not be shared verbally, via email, or via chat
7MinSec follows the NIST compromise-driven approach to password expiration, requiring a password to be changed only when it is known or suspected to be compromised, rather than on a fixed schedule. The company-designated password manager continuously checks stored credentials against public breach data and flags any that are known to be exposed. These findings are reviewed at least monthly, alongside the access review in Section 9, and any affected credential is rotated on discovery.
4.2 Multi-Factor Authentication (MFA)
- MFA is mandatory for every account a person signs in to, without exception
- MFA is enforced on the productivity suite, file storage, report authoring platform, password manager, remote access, and all other cloud services
- Authenticator app-based MFA (TOTP) is preferred; SMS-based MFA is discouraged where alternatives exist
Non-interactive service and automation accounts cannot present a second factor. These authenticate by key pairs rather than passwords, are restricted to named source addresses at the network boundary, and are granted only the access their function requires. Each such account is recorded, with its justification and its source restriction, in the asset inventory. No interactive account is exempt from multi-factor authentication on this basis.
4.3 Client Environment Access
- All access to internal client environments is conducted exclusively through MFA-protected, zero-trust remote access, restricted to named users
- No client environment is accessed from unsecured or public networks except through that zero-trust remote access
- Client-provided credentials used during engagements are stored in the password manager and deleted immediately upon engagement close
5. Access Provisioning
All access for subcontractors, and for any personnel engaged in future, is provisioned only on the President's written approval given in advance, by email or through a ticket. Any change to the access held by an existing account requires the same written approval before it is made. Approvals are retained and form the record of why an account holds the access it does. Access is never granted on a verbal request.
6. Report Authoring Platform Access Controls
7MinSec authors penetration test reports on a self-hosted platform. It receives special access controls given the sensitive nature of its contents:
- The platform is hosted on 7MinSec-managed infrastructure and is not publicly accessible
- Firewall rules restrict access to known, pre-approved subcontractor public IP addresses only
- Any new subcontractor IP must be submitted to Brian Johnson and allowlisted before access is granted
- Access is reviewed at the start of each engagement and revoked when no longer needed
7. Endpoint Requirements
7MinSec operates a BYOD model. Both 7MinSec-managed endpoints and subcontractor-owned endpoints are used to access 7MinSec systems and client environments. A common baseline applies to every device, and 7MinSec-managed endpoints carry two additional controls.
This section governs the endpoints used to access 7MinSec systems and client environments. Server and network infrastructure operated by 7MinSec is not covered by the endpoint baseline in Section 7.1, but is covered by the hardening standards in Section 7.4.
7.1 Baseline for every device
No device is granted access until it meets all of the following:
- Multi-factor authentication on every account a person signs in to for 7MinSec or client work, without exception. Non-interactive service accounts are covered by Section 4.2
- Credentials held only in the company-designated password manager, under a 7MinSec-managed account
- Active malware protection with automatic signature updates. On Windows endpoints this is an endpoint protection product with real-time protection enabled. On macOS endpoints this is the operating system's built-in malware protection, together with code-signing enforcement and system integrity protection, all of which update automatically from the vendor
- A host-based or network firewall enabled, denying inbound connections that are not explicitly required
- Automatic execution of removable media disabled. On Windows this means AutoRun and AutoPlay are disabled by policy for all drive types; macOS has no equivalent facility to disable
- Full-disk encryption enabled
- Only vendor-supported operating systems and licensed software are installed
- Operating system and all software current with security patches. Security-relevant updates are applied within the following maximum timeframes from vendor release: Critical 7 days, High 30 days, Medium 60 days, Low 90 days
- Automatic lock after no more than 15 minutes of inactivity
- Client environments reached only through MFA-protected, zero-trust remote access
7.2 Additional controls on 7MinSec-managed endpoints
- Application allowlisting installed and enforced on a deny-all, permit-by-exception basis, so software not explicitly authorized cannot execute
- Security telemetry forwarded to 7MinSec's centralized security monitoring platform, giving central visibility of authentication, privilege use, patch state, and system integrity events
7.3 Compensating controls for subcontractor devices
Subcontractor-owned devices do not run application allowlisting and are not enrolled in centralized monitoring. That difference is addressed at the perimeter rather than on the endpoint:
- Zero-trust remote access restricted to named individual users, federated to 7MinSec's identity provider where MFA is enforced
- Address-restricted access to the report authoring platform
- Access granted for the duration of an engagement only, and revoked immediately at close
- Control-by-control attestation before the first engagement and annually thereafter, via the 7MinSec Subcontractor Security Acknowledgment form
Where an engagement requires centrally managed and monitored testing systems, 7MinSec can provide a dedicated assessment host under 7MinSec or client control rather than working from subcontractor-owned equipment.
7.4 System Hardening Standards
7MinSec maintains documented hardening standards for each type of system it operates: workstations by operating system, servers, virtual machines, and network devices. Each standard identifies the published baseline it derives from, records any deviation from that baseline together with the reason, and is reviewed at least annually. Systems are provisioned in accordance with the standard for their type before being granted access to 7MinSec systems or client environments.
These standards are established by January 1, 2027.
8. Privileged Access
- Multi-factor authentication is enforced on every privileged account, without exception
- Authenticator applications or hardware security keys are the required second factor on privileged accounts. 7MinSec is auditing every privileged account to identify and remove SMS-based one-time codes, including where SMS remains configured only as an account recovery method. That audit completes, and SMS is removed wherever the provider permits it, by January 1, 2027. Where a provider does not permit removal, the account and the reason are recorded and compensating controls are applied
- Privileged accounts must be separate from standard user accounts where technically feasible
- Privileged credentials are stored in a dedicated password manager vault with restricted access
- Use of privileged access is limited to tasks that specifically require it
- Privileged access to client systems during engagements is documented in the engagement record and revoked upon close
9. Access Review
Brian Johnson (President) reviews active access rights at least quarterly and at the close of every engagement to confirm all active accounts are associated with current personnel or active engagements, access levels remain appropriate, and no stale or orphaned accounts exist.
In addition to the quarterly review, accounts are reviewed monthly for inactivity. Any account showing no activity for 45 days is disabled unless a documented business reason exists to retain it. Disabled accounts are removed at the next quarterly review.
The same monthly review covers the password manager's breach findings, as described in Section 4.1.
10. Violations
Sharing credentials, bypassing MFA, accessing systems beyond authorized scope, or retaining access beyond an engagement are serious violations of this policy. Such violations may result in immediate termination of the subcontractor relationship and notification to the affected client.
11. Policy Review
This policy is reviewed annually or following any access-related security incident, significant personnel change, or addition of new tools. The current version is published in the 7MinSec Trust Center.
Policy Approval
The signed master copy of this policy is maintained in Word format and is available to customers and partners on request.
Change Log
This log records all changes made to this policy over time.
Document Feedback
To suggest changes to this policy or report an issue, contact: security@7minsec.com
Last reviewed: October 2, 2026