1. Purpose
This policy sets out Murzo Group's approach to access control, passwords, passkeys, multi-factor authentication, privileged access, account lifecycle management, and access reviews.
The purpose is to reduce unauthorised access, protect confidential information and personal data, support business continuity, and improve security across Murzo Group systems and third-party platforms.
2. Scope
This policy applies to Murzo Group workers, directors, contractors, suppliers, administrators, service providers, and authorised third parties who access Murzo Group systems, cloud services, websites, email, files, platforms, development tools, domains, social media accounts, or business records.
3. Access Principles
Access must be granted, changed, reviewed, and removed using a risk-based and documented approach.
- Least privilege: users should only receive access needed for their role or task
- Need to know: sensitive information should only be available to authorised people
- Segregation of duties: conflicting roles should be separated where practical
- Unique accountability: shared accounts should be avoided unless formally controlled
- Timely removal: access must be removed when no longer required
4. Joiners, Movers & Leavers
Murzo Group will manage account creation, role changes, and account removal through suitable joiner, mover, and leaver controls.
When a user changes role, project, supplier relationship, or employment status, access should be reviewed and adjusted. Departing users must have access revoked promptly according to risk.
5. Passwords, Passphrases & Passkeys
Passwords and passphrases must be strong, unique, and protected. Reuse of Murzo Group passwords on personal or third-party accounts is prohibited.
Where available and appropriate, Murzo Group may use password managers, passkeys, single sign-on, and other modern authentication controls to reduce password risk.
- Passwords must not be shared, written in exposed locations, sent through insecure channels, or stored in plain text
- Default passwords must be changed before use
- Compromised or suspected compromised passwords must be changed promptly
- Password reset processes must verify identity using suitable controls
- Users should not approve login prompts they did not initiate
6. Multi-Factor Authentication
Multi-factor authentication should be enabled for important systems, administrator accounts, email, cloud services, financial systems, domain accounts, social media accounts, remote access, and other high-risk services wherever practicable.
MFA methods should be protected from loss, theft, social engineering, prompt fatigue, SIM-swap risk, and unauthorised transfer.
7. Privileged & Administrator Access
Privileged access must be limited, approved, protected, and reviewed more carefully than normal user access.
Administrator accounts should not be used for routine work where separate standard accounts are available. Emergency administrator access should be controlled, logged where possible, and reviewed after use.
8. Third-Party & Supplier Access
Third-party access must be authorised, limited to agreed purposes, time-bound where practicable, and removed when no longer needed.
Suppliers with access to systems, data, source material, product information, or confidential records may be required to meet security, confidentiality, insurance, and incident-notification requirements.
9. Logging, Review & Monitoring
Murzo Group may monitor account activity, access logs, authentication events, administrator actions, and permission changes where lawful and proportionate.
Access should be reviewed periodically for important systems, high-risk users, privileged roles, third-party accounts, and sensitive information repositories.
10. Incidents & Enforcement
Suspected account compromise, unauthorised access, credential sharing, MFA compromise, privilege misuse, or access control failure must be reported promptly.
Murzo Group may suspend accounts, reset credentials, revoke sessions, restrict access, investigate activity, preserve logs, notify affected parties, or take disciplinary or contract action where required.
11. Review & Responsibilities
Users are responsible for protecting credentials and following access rules. Managers, system owners, and authorised representatives are responsible for approving, reviewing, and removing access.
This policy will be reviewed periodically and after significant technology, supplier, legal, or threat changes.