Access Management Policy: Business Tools/Services
Objective:
The purpose of this policy is to establish guidelines for access management to third-party tools and services used by Outleap. The policy aims to ensure the security and privacy of the organization's data and systems while granting access to authorized personnel.
Account Creation and Administration:
New accounts for third-party tools/services shall be created using the email address tech@leapfinance.com
For existing accounts, the email address tech@leapfinance.com shall be designated as the admin/owner of the account, where applicable.
-
Exception in below cases
Payment is done per email ID subscription, and there is no separate owner/billing account. (Not centralised)
Sensitive data which can’t be shared with other employees (for example, HR tools like Keka, etc)
Login Authentication:
Login with Gmail shall be the preferred method of authentication, where supported by the third-party tool/service. Whenever feasible, employees should use their Leap Finance Gmail accounts for these tools.
In cases where login with Gmail is not feasible, strict password policies shall be enforced. Passwords must meet the following requirements:
Minimum password length: 10 characters
Use a combination of uppercase and lowercase letters, numbers, and special characters.
Passwords must be changed every 90 days.
Password Sharing:
Avoid Common Team Email IDs:
Nomination of Access Owners for Team Level Executables:
Knowledge Transfer and Account Dependencies:
Account Cleanup after Employee Exit:
The IT team shall ensure the immediate cleanup of access for any employee who leaves the organization. The IT team will follow an exit checklist to revoke access to all third-party tools/services associated with the employee's account.
For tools where the IT team does not have access to perform user access cleanup, the respective reporting manager has to ensure access cleanup.
Regular Review and Cleanup:
The IT team, in collaboration with the concerned departments, shall regularly review access permissions to third-party tools/services and perform cleanup activities to ensure compliance with this policy.
Exceptions and Support:
Policy Compliance:
Policy Review:
Note:
All employees are expected to read, understand, and adhere to this Access Management Policy for Third-Party Tools/Services. It is the responsibility of each employee to ensure the security and privacy of the organization's data and systems while using these tools/services.