A city allows vendor engineers into internal systems for after-hours repairs but rarely watches those sessions. What oversight should be added to third-party communication channels?
Select an answer to reveal the explanation.
Short Explanation
Vendor after-hours access without a clock, a log, or a watcher is unsupervised keys to the building. Bound the session, record what happens, and require logical escort or dual approval—don’t give forever tunnels or rely on monthly pinky-swears. Hiding accounts from the directory only hides the risk from you.
Full Explanation
Third-party channels require continuous oversight: temporary access windows, comprehensive logging or session recording, and human or system escort patterns that prevent unsupervised privileged activity. Standing always-on vendor tunnels expand persistent exposure and weaken accountability. Self-attestation without technical monitoring is insufficient for high-risk support paths. Concealing accounts from directories undermines identity governance and auditability of third-party connectivity.