Access Management Policy

How 7 Minute Security grants, manages, monitors, and revokes access to its systems, tools, and client environments.
Version Effective Approved Last reviewed Owner
1.4 October 2, 2026 October 2, 2026 October 2, 2026 Brian Johnson, President

1. Purpose

Access to systems, data, and client environments is one of the highest-risk areas for a cybersecurity services firm. This policy defines how 7MinSec grants, manages, monitors, and revokes access, ensuring that only the right people have access to the right resources at the right time.

2. Scope

This policy applies to all 7MinSec personnel and subcontractors accessing 7MinSec internal systems (productivity suite, file storage, report authoring platform, password manager, etc.), client networks and systems during authorized engagements, and any cloud services or SaaS tools used in the delivery of 7MinSec services.

3. Guiding Principles

Principle Description
Least Privilege Grant only the minimum access required to perform a specific task
Need to Know Access to client data is limited to personnel on the relevant engagement
Zero Trust No implicit trust is granted based on network location or prior access
Time-Limited Access Access to client environments is granted for the duration of an engagement only
Accountability All access is tied to individually identifiable accounts, with no shared credentials

4. Authentication Requirements

4.1 Passwords

  • All 7MinSec personnel and subcontractors must use the company-designated enterprise password manager
  • All passwords must be unique, randomly generated, and never reused across accounts
  • Passwords are a minimum of 12 characters where the account is protected by multi-factor authentication, and a minimum of 16 characters where multi-factor authentication cannot be enabled on the account
  • Passwords are generated by the password manager using its full character set, covering upper case, lower case, numeric, and special characters. Where a password must be typed from memory, such as a device login or the password manager's own master password, it is a passphrase of at least 16 characters
  • Passwords must not be shared verbally, via email, or via chat

7MinSec follows the NIST compromise-driven approach to password expiration, requiring a password to be changed only when it is known or suspected to be compromised, rather than on a fixed schedule. The company-designated password manager continuously checks stored credentials against public breach data and flags any that are known to be exposed. These findings are reviewed at least monthly, alongside the access review in Section 9, and any affected credential is rotated on discovery.

4.2 Multi-Factor Authentication (MFA)

  • MFA is mandatory for every account a person signs in to, without exception
  • MFA is enforced on the productivity suite, file storage, report authoring platform, password manager, remote access, and all other cloud services
  • Authenticator app-based MFA (TOTP) is preferred; SMS-based MFA is discouraged where alternatives exist

Non-interactive service and automation accounts cannot present a second factor. These authenticate by key pairs rather than passwords, are restricted to named source addresses at the network boundary, and are granted only the access their function requires. Each such account is recorded, with its justification and its source restriction, in the asset inventory. No interactive account is exempt from multi-factor authentication on this basis.

4.3 Client Environment Access

  • All access to internal client environments is conducted exclusively through MFA-protected, zero-trust remote access, restricted to named users
  • No client environment is accessed from unsecured or public networks except through that zero-trust remote access
  • Client-provided credentials used during engagements are stored in the password manager and deleted immediately upon engagement close

5. Access Provisioning

All access for subcontractors, and for any personnel engaged in future, is provisioned only on the President's written approval given in advance, by email or through a ticket. Any change to the access held by an existing account requires the same written approval before it is made. Approvals are retained and form the record of why an account holds the access it does. Access is never granted on a verbal request.

Scenario Process Timing
New subcontractor onboarding Partnership Agreement and Security Acknowledgment signed → Brian Johnson provisions access to relevant tools only Before engagement start
New client engagement Scope confirmed → remote access configured → credentials issued to relevant personnel only At engagement kickoff
Access level change Request to Brian Johnson → justification reviewed → access adjusted As needed
Offboarding Engagement ends or subcontractor departs → all access revoked Immediately at engagement close or departure

6. Report Authoring Platform Access Controls

7MinSec authors penetration test reports on a self-hosted platform. It receives special access controls given the sensitive nature of its contents:

  • The platform is hosted on 7MinSec-managed infrastructure and is not publicly accessible
  • Firewall rules restrict access to known, pre-approved subcontractor public IP addresses only
  • Any new subcontractor IP must be submitted to Brian Johnson and allowlisted before access is granted
  • Access is reviewed at the start of each engagement and revoked when no longer needed

7. Endpoint Requirements

7MinSec operates a BYOD model. Both 7MinSec-managed endpoints and subcontractor-owned endpoints are used to access 7MinSec systems and client environments. A common baseline applies to every device, and 7MinSec-managed endpoints carry two additional controls.

This section governs the endpoints used to access 7MinSec systems and client environments. Server and network infrastructure operated by 7MinSec is not covered by the endpoint baseline in Section 7.1, but is covered by the hardening standards in Section 7.4.

7.1 Baseline for every device

No device is granted access until it meets all of the following:

  • Multi-factor authentication on every account a person signs in to for 7MinSec or client work, without exception. Non-interactive service accounts are covered by Section 4.2
  • Credentials held only in the company-designated password manager, under a 7MinSec-managed account
  • Active malware protection with automatic signature updates. On Windows endpoints this is an endpoint protection product with real-time protection enabled. On macOS endpoints this is the operating system's built-in malware protection, together with code-signing enforcement and system integrity protection, all of which update automatically from the vendor
  • A host-based or network firewall enabled, denying inbound connections that are not explicitly required
  • Automatic execution of removable media disabled. On Windows this means AutoRun and AutoPlay are disabled by policy for all drive types; macOS has no equivalent facility to disable
  • Full-disk encryption enabled
  • Only vendor-supported operating systems and licensed software are installed
  • Operating system and all software current with security patches. Security-relevant updates are applied within the following maximum timeframes from vendor release: Critical 7 days, High 30 days, Medium 60 days, Low 90 days
  • Automatic lock after no more than 15 minutes of inactivity
  • Client environments reached only through MFA-protected, zero-trust remote access

7.2 Additional controls on 7MinSec-managed endpoints

  • Application allowlisting installed and enforced on a deny-all, permit-by-exception basis, so software not explicitly authorized cannot execute
  • Security telemetry forwarded to 7MinSec's centralized security monitoring platform, giving central visibility of authentication, privilege use, patch state, and system integrity events

7.3 Compensating controls for subcontractor devices

Subcontractor-owned devices do not run application allowlisting and are not enrolled in centralized monitoring. That difference is addressed at the perimeter rather than on the endpoint:

  • Zero-trust remote access restricted to named individual users, federated to 7MinSec's identity provider where MFA is enforced
  • Address-restricted access to the report authoring platform
  • Access granted for the duration of an engagement only, and revoked immediately at close
  • Control-by-control attestation before the first engagement and annually thereafter, via the 7MinSec Subcontractor Security Acknowledgment form

Where an engagement requires centrally managed and monitored testing systems, 7MinSec can provide a dedicated assessment host under 7MinSec or client control rather than working from subcontractor-owned equipment.

7.4 System Hardening Standards

7MinSec maintains documented hardening standards for each type of system it operates: workstations by operating system, servers, virtual machines, and network devices. Each standard identifies the published baseline it derives from, records any deviation from that baseline together with the reason, and is reviewed at least annually. Systems are provisioned in accordance with the standard for their type before being granted access to 7MinSec systems or client environments.

These standards are established by January 1, 2027.

8. Privileged Access

  • Multi-factor authentication is enforced on every privileged account, without exception
  • Authenticator applications or hardware security keys are the required second factor on privileged accounts. 7MinSec is auditing every privileged account to identify and remove SMS-based one-time codes, including where SMS remains configured only as an account recovery method. That audit completes, and SMS is removed wherever the provider permits it, by January 1, 2027. Where a provider does not permit removal, the account and the reason are recorded and compensating controls are applied
  • Privileged accounts must be separate from standard user accounts where technically feasible
  • Privileged credentials are stored in a dedicated password manager vault with restricted access
  • Use of privileged access is limited to tasks that specifically require it
  • Privileged access to client systems during engagements is documented in the engagement record and revoked upon close

9. Access Review

Brian Johnson (President) reviews active access rights at least quarterly and at the close of every engagement to confirm all active accounts are associated with current personnel or active engagements, access levels remain appropriate, and no stale or orphaned accounts exist.

In addition to the quarterly review, accounts are reviewed monthly for inactivity. Any account showing no activity for 45 days is disabled unless a documented business reason exists to retain it. Disabled accounts are removed at the next quarterly review.

The same monthly review covers the password manager's breach findings, as described in Section 4.1.

10. Violations

Sharing credentials, bypassing MFA, accessing systems beyond authorized scope, or retaining access beyond an engagement are serious violations of this policy. Such violations may result in immediate termination of the subcontractor relationship and notification to the affected client.

11. Policy Review

This policy is reviewed annually or following any access-related security incident, significant personnel change, or addition of new tools. The current version is published in the 7MinSec Trust Center.

Change Log

This log records all changes made to this policy over time.

Version Date Author Description of Change
1.0 September 1, 2026 Brian Johnson Initial release.
1.1 September 23, 2026 Brian Johnson Restructured Section 7 into a two-tier endpoint baseline: Section 7.1 applies to every device, Section 7.2 adds application allowlisting and centralized security monitoring on 7MinSec-managed endpoints, and Section 7.3 states the compensating perimeter controls that apply to subcontractor-owned equipment. Corrected the device auto-lock requirement from 5 minutes to 15 minutes to match our actual configuration. Added maximum patch remediation timeframes by severity: Critical 7 days, High 30, Medium 60, Low 90. Corrected Section 5 and Section 7 to describe accurately what the subcontractor Partnership Agreement covers and where control attestation actually comes from.
1.1.1 September 24, 2026 Brian Johnson Corrected the Section 7.1 endpoint protection requirement to describe the malware protection actually in place on each platform, rather than describing it as centrally managed. Clarified in the Section 7 preamble that the endpoint baseline governs devices used to access 7MinSec systems, not 7MinSec server and network infrastructure. Editorial pass ahead of publication: em dashes removed throughout. No other requirement changed.
1.2 September 28, 2026 Brian Johnson Incorporated recommendations from an independent policy review against the CIS Controls. Section 4.1 adds minimum password lengths, describes how passwords are generated, and adopts a compromise-driven approach to expiration with a monthly review of the password manager's breach findings. Section 5 requires written approval in advance for access granted to subcontractors and future personnel. Revocation at engagement close or departure is now immediate rather than within 24 hours, in Sections 5 and 7.3. Section 7.1 adds a host or network firewall, disabled automatic execution of removable media, and vendor-supported and licensed software only. New Section 7.4 requires documented system hardening standards, established by January 1, 2027. Section 8 requires multi-factor authentication on privileged accounts and prohibits SMS-based codes on them, with the removal audit completing by January 1, 2027. Section 9 adds a monthly review for inactive accounts.
1.3 October 2, 2026 Brian Johnson Independent review of v1.2 completed with no further changes requested, and 7MinSec's own accuracy review completed with no findings. Added a provision to Section 4.2 for non-interactive service and automation accounts, which authenticate by key pair with restricted source addresses rather than by multi-factor authentication, and are recorded individually with their justification. Section 7.1 states multi-factor authentication on every account with no exceptions, which did not describe automated service authentication accurately.
1.4 October 2, 2026 Brian Johnson Corrected Sections 4.2 and 7.1, which both stated multi-factor authentication on every account with no exceptions while Section 4.2 also described non-interactive service accounts that cannot present a second factor. Both now scope the requirement to accounts a person signs in to, and Section 7.1 points at Section 4.2 for service accounts. The v1.3 change log identified this inconsistency in Section 7.1 but the wording was not corrected at the time.

Last reviewed: October 2, 2026