C&A / IAM question: should “non-production” trial accounts be tested against live data access?
In a system handling sensitive personal data, suppose a class of trial accounts was deliberately excluded from pre-production access-control testing because those accounts were not intended to access production. After launch, it was discovered that hundreds of those trial accounts were technically capable of accessing all live reporting records.
From a security assurance / C&A / IAM perspective:
- Would excluding those accounts from effective-access testing normally be considered an assurance scope gap?
- Is “these accounts were not intended to access production” normally enough reason not to test whether they actually could?
- Would you expect negative authorisation testing to verify that non-production/trial account types cannot reach production data?
- Would this normally be characterised as a testing failure, configuration failure, assurance failure, or some combination?
- What records would you expect to exist afterwards to establish where the control failed?
[link] [comments]