LOGICAL ACCESS CONTROL POLICIES Clause Samples

LOGICAL ACCESS CONTROL POLICIES. 4.1 Abstract The logical access control consists of four pillars: These are identification, authentication, authorization, and last but not least monitoring. Authorization is based on a person identified by a user ID well authenticated, whom are granted the system privileges and / or the access rules necessary to perform her / his task. In terms of baseline controls, authentication by password can be considered as a good minimum security level, provided the management of the user IDs, password and authorization are compliant with the policies presented below. By ensuring that only an involved end user knows his or her own password, it permits system activity logged with a corresponding personal user ID to be uniquely attributable to a certain user. The information owner is responsible for validating access requests to her or his applications and data. The hereafter policies are structured based on the four access control pillars: 1. Identification 2. Authentication 3. Authorization 4. Monitoring