CISO · Compliance Manager

Is access to production data taken as seriously as identity?

Your identity side is probably mature. The gap is not unauthorised access. It is an authorised person acting without a rule.

How this question is answered today

Identity management is in place. Privileges are defined, access is reviewed, privileged accounts are monitored.

Then a manager asks for some data. An authorised person runs a permitted query, puts the result in a file and sends it. No rule is broken.

Who took which data for what stated reason, which fields went out in the clear, and where the file ended up are nowhere recorded together.

What that answer costs

The personal data access trail is reconstructed after the fact. A reconstructed trail is not evidence.
The masking decision is left to a person. The same column can go out masked in one delivery and open in the next.
When data leaves the organisation, there is no record showing the destination address was ever approved.
In an incident investigation the scope cannot be set: if you do not know who saw what, you cannot know the impact.

What governance changes

Reading production data is treated as seriously as changing it: request, reason, approval and delivery live in a single record.

Which field is masked stops being a person's decision and becomes the rule's decision. If a field goes out in the clear, that approval is recorded separately.

Evidence is not gathered afterwards. The delivery produces the record, and that record can be verified from outside the system that keeps it.

Access to production data is treated as seriously as identity, and the trail for personal data access creates itself.