Entitlements in degraded mode
The commonest blocker
In measured recovery tests, the leading cause of stoppage is almost never hardware. It is access: an expired administration password, a multi-factor token tied to a phone left at the office, an application entitlement only production can grant.
These blockers are invisible in normal operations, because access there is granted continuously.
The four accesses to prepare
Access to the recovery infrastructure. Console, hypervisor, storage. With accounts distinct from production's, since the compromise scenario assumes those are unusable.
Access to the backup. The most critical, and the most often circular: the backup console authenticates against the production directory.
Physical access. Badges, codes, keys to the recovery site. A badge deactivated because the holder changed role blocks arrival on site at 3 a.m.
Access to third parties. Supplier portals, support lines, client certificates registered with partners. These accesses are personal and follow people, not roles.
Break-glass accounts
They exist, they are physically recorded outside the information system, and their use is detectable. Three rules:
- Escrow: sealed envelope, safe, or a digital vault independent of the domain.
- Periodic rotation with traceability of who performed it.
- Alert on use: any break-glass access outside a declared crisis is an incident to investigate.
Exception access during the crisis
ISO/IEC 27001 control A.5.29 forbids disabling controls during a disruption. The crisis procedure must therefore provide exception access that is logged, time-limited and automatically revoked, rather than a suspension of the rules.
In practice: a temporary role with a four-hour lifetime, granted by somebody other than the beneficiary, logged, and reviewed on return to normal.
Key takeaways
- A recovery is blocked more often by an access than by a server
- Break-glass accounts must be recorded outside the information system
- Exception access must be logged, time-limited and automatically revoked