Contractor Abuse
Contractor access abuse arises when a consultant, a contractor, an external firm or a temporarily engaged person uses access more widely or for longer than the work requires. The access is often granted legitimately, but afterwards it is not monitored, not narrowed and not withdrawn in time.
Term
description · examples · notesContractor access abuse arises when a consultant, a contractor, an external firm or a temporarily engaged person uses access more widely or for longer than the work requires. The access is often granted legitimately, but afterwards it is not monitored, not narrowed and not withdrawn in time.
Description
External associates can hold access to code, production systems, client data, the VPN, support tools or documentation. Unlike employees they are often outside the same regime of training, oversight, HR process and discipline. When the contract ends, the account sometimes stays open.
The risk is not only deliberate theft. A private laptop with no protection is enough, or keeping data for the next project, or sharing an account inside the supplier's own firm, or access nobody holds in any record any more. The external associate becomes a blind spot in the network of trust.
Examples
- An external developer copies the project's source code and uses it later on another engagement.
- A consultant keeps VPN access for months after the contract has ended.
- A supplier firm shares one support account among several of its own employees, without the client's knowledge.
Notes
- Access for external associates has to have an expiry date.
- A plumber does not get a key to the house for coming once a month to fix a tap.
Techniques
carried out with 2Techniques used to carry it out. Select one to open its page.
Defenses
countered by 4How it is defended against. Select one to open its page.