Access control
- People receive only the access their role requires.
- End users, administrators, and service accounts remain separate.
- Access is reviewed when roles, staff, or project ownership change.
Security
Security decisions are matched to the information, users, hosting environment, and risk of the project.