Posts

Showing posts with the label Management of Privileged Access Rights

ISO 27001 Annex : A.9.2.3 Management of Privileged Access Rights & A.9.2.4 Management of Secret Authentication Information of Users

Image
ISO 27001 Annex : A.9.2.3 Management of Privileged Access Rights & A.9.2.4 Management of Secret Authentication Information of Users these two topic is explained in this article. A.9.2.3 Management of Privileged Access Rights Control-  A.9.2.3 Management of Privileged Access Rights The allocation and usage of exclusive access privileges will be limited and controlled. Implementation guidance-  A structured authorizing procedure in accordance with the appropriate access management  policies  should monitor the allocation and usage of delegated access privileges. Following steps should be taken into consideration: The privileges of access associated with each system or process, e.g. The operating system, the database management system and each application and the users to whom they need to be assigned should be identified; Preferential access privileges would be assigned to users on a need-to-use basis and on an event-to-event basis in accordance wit...