Posts

Showing posts with the label Cryptographic Encryption

ISO 27001 Annex : A.9.4 System and Application Access Control

Image
ISO 27001 Annex : A.9.4 System and Application Access Control  Its objective is  to put a stop to unauthorized access to systems and applications. A.9.4.1 Information Access Restriction Control-  Access to information and application system functions should be limited in compliance with the policy on access control. Implementation Guidance-  Access controls  should be based on individual requirements for business applications and in compliance with a specified access control policy. In order to meet access restriction criteria, the following should be considered:- Provide menus for controlling access to application system functions; Controlling which data a particular user can access; Control  user access  permission, e.g. read, write, delete, and execute; Control of the access permission to other applications; Restrict the information contained in the outputs; Physical or logical access controls for sensitive applications, applicat...