CISO · Compliance Manager

Üretim verisine erişim, kimlik yönetimi kadar ciddiye alınıyor mu? Is access to production data taken as seriously as identity?

Kimlik tarafınız muhtemelen olgun. Boşluk yetkisiz erişimde değil, yetkili kişinin kuralsız işleminde. Your identity side is probably mature. The gap is not unauthorised access. It is an authorised person acting without a rule.

Bugün bu soru nasıl cevaplanıyorHow this question is answered today

Kimlik yönetimi yerinde. Yetkiler tanımlı, erişim gözden geçiriliyor, ayrıcalıklı hesaplar izleniyor.

Identity management is in place. Privileges are defined, access is reviewed, privileged accounts are monitored.

Sonra bir yönetici bir veri istiyor. Yetkili bir kişi, izinli bir sorgu çalıştırıyor, sonucu bir dosyaya alıp gönderiyor. Hiçbir kural ihlal edilmiyor.

Then a manager asks for some data. An authorised person runs a permitted query, puts the result in a file and sends it. No rule is broken.

Bu işlemde kimin hangi gerekçeyle hangi veriyi aldığı, hangi alanların açık gittiği ve dosyanın nereye ulaştığı hiçbir yerde birlikte durmuyor.

Who took which data for what stated reason, which fields went out in the clear, and where the file ended up are nowhere recorded together.

Bu cevabın maliyetiWhat that answer costs

Kişisel veriye erişimin izi sonradan inşa ediliyor. İnşa edilen iz, kanıt değildir.The personal data access trail is reconstructed after the fact. A reconstructed trail is not evidence.
Maskeleme kararı kişiye kalıyor. Aynı kolon bir teslimde maskeli, diğerinde açık gidebiliyor.The masking decision is left to a person. The same column can go out masked in one delivery and open in the next.
Veri kurum dışına çıktığında, hangi adrese gittiğinin onaylandığını gösterecek bir kayıt yok.When data leaves the organisation, there is no record showing the destination address was ever approved.
Bir olay incelemesinde kapsam belirlenemiyor: kimin neyi gördüğü bilinmiyorsa etki de bilinemiyor.In an incident investigation the scope cannot be set: if you do not know who saw what, you cannot know the impact.

Yönetişim bunu nasıl değiştirirWhat governance changes

Üretim verisi okuma işlemi, değişiklik kadar ciddi bir işlem olarak ele alınır: talep, gerekçe, onay ve teslim tek kayıtta durur.

Reading production data is treated as seriously as changing it: request, reason, approval and delivery live in a single record.

Hangi alanın maskeleneceği kişinin kararı olmaktan çıkar, kuralın kararı olur. Bir alan açık gidecekse bunun onayı ayrıca kayda geçer.

Which field is masked stops being a person's decision and becomes the rule's decision. If a field goes out in the clear, that approval is recorded separately.

Kanıt sonradan toplanmaz. Teslimin kendisi kaydı üretir ve bu kayıt, kaydı tutan sistemin dışından doğrulanabilir.

Evidence is not gathered afterwards. The delivery produces the record, and that record can be verified from outside the system that keeps it.

Üretim verisine erişim kimlik yönetimi kadar ciddiye alınır ve kişisel veriye erişimin izi kendiliğinden oluşur. Access to production data is treated as seriously as identity, and the trail for personal data access creates itself.