Skip to main content

Administrator Privileges

Network and/or system administrators are responsible for keeping the company network infrastructure effectively maintained. They are typically involved in the procurement of new hardware, the roll out of new software, maintaining server installations and applications, monitoring the performance of the network, checking for security breaches and improper data management practices. Typically, within a larger company, these roles are split and assigned to multiple personnel across various functions or departments. Within smaller companies, the responsibilities may be assigned to a single individual and it is also common to outsource this function to a third party.

Administrator privileges

An important step in providing security for your network is to establish and enforce administrator privileges. Inappropriate use of administrator privileges is often found to be a major contributory factor to data breaches or corruption of data. In small and medium-sized businesses, administrators often assume numerous job functions and have access rights and passwords for multiple platforms or systems. This can pose a security concern if the administrative privileges are not properly controlled, making it easier for an attacker to gain full control of systems. To minimize this exposure, risk management considerations include, but are not limited to:

  • Enable Multi-Factor Authentication (MFA) for all privileged and admin access for all devices whether accessing internally or remotely.
  • Restrict authorization of administrator privileges to senior management. Restrict the allocation of administrator privileges to specific equipment or applications that are aligned with responsibilities. If the administrator requires wider privileges, to perform a specific task, consider allowing that privilege only for a limited time.
  • Any changes made by the administrator to enable or disable security features or to change user privileges should be approved by senior management.
  • Requirements should be established to specify that the administrator passwords should be more complex and changed more frequently in recognition of their responsibility. Administrator passwords should also be different than their user passwords.
  • Administrators should maintain separate user accounts for their daily use and their administrator specific work. They should not be allowed to access the Internet or email from their privileged administrator accounts.
  • If services are outsourced to third parties, address the proper protection and control administrator access. Also consider incorporating terms in the contract to hold third-party providers accountable and professionally liable for their services.
    • Third parties should be restricted from using the same administrative passwords at multiple client locations because this can put your network at risk if the password is compromised at one of the other client locations.
    • Requiring two-factor authentication for all third-party or remote administrators to gain access should be considered.  

Related resources

User Access Priviliges and Control Policies

This article discusses the importance of data access and controls as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related resources

Network Logging and Monitoring

Company networks should be protected against employee accidental or intentional actions, as well as cyber threats originating outside the company.

Related resources

Third-Party Cyber Security Vendor Management

This article discusses the importance of third-party service providers in data security as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.