Controls & Security

This page documents access controls, cybersecurity practices, and data backup procedures for SHHA systems.

Items marked TODO need information filled in. These questions originated from Andrea's controls review.

Access Controls — Who Has Access to What?

Microsoft 365 Admin Access

Global AdministratorTODO: Who currently has Global Admin access? (There should be a primary and a backup.)
User / Group managementAnna (office staff) manages day-to-day membership. IT admin handles mailbox permissions.
Who manages access?TODO: Is there a documented process for granting/revoking admin access? Who approves changes?

Other System Access

SystemPrimary AccessBackup Access
QuickBooksTODOTODO
Membership DatabaseTODOTODO
Gusto (Payroll)TODOTODO
SHHA Website (admin)TODOTODO
SquareTODOTODO
Domain registrarTODOTODO
Google accountsTODOTODO

Cybersecurity

Current Practices

Data Access

Data Backup

Cloud-Based Systems

Most SHHA data resides in cloud services. Each provider has its own backup/redundancy:

SystemBackup Approach
Microsoft 365 (email, SharePoint)Microsoft provides built-in redundancy and retention policies. TODO: Do we have a separate backup solution (e.g., third-party M365 backup)? What are our retention policy settings?
QuickBooks OnlineIntuit maintains backups. TODO: Do we also export periodic backups locally?
GustoGusto maintains payroll records. TODO: Do we keep local copies of payroll reports?
SHHA WebsiteTODO: Who backs up the website? How often? Where are backups stored?
Membership DatabaseTODO: How is the membership database backed up?

Local Data

Other Security Considerations


Revision #1
Created 2026-04-01 05:06:44 UTC by BookStackBot
Updated 2026-04-01 05:06:44 UTC by BookStackBot