Logical Access Controls Clause Samples

The Logical Access Controls clause establishes requirements for managing and restricting access to information systems and data through electronic means. It typically mandates the use of authentication methods such as passwords, user IDs, or multi-factor authentication, and may specify procedures for granting, modifying, or revoking user access based on roles or job responsibilities. By defining how access is controlled and monitored, this clause helps prevent unauthorized access, thereby protecting sensitive information and reducing the risk of data breaches.
Logical Access Controls. Trane employs internal monitoring and logging technology to help detect and prevent unauthorized access attempts to Trane’s corporate networks and production systems. Trane’s monitoring includes a review of changes affecting systems’ handling authentication, authorization, and auditing, and privileged access to Trane production systems. ▇▇▇▇▇ uses the principle of “least privilege” (meaning access denied unless specifically granted) for access to customer data.
Logical Access Controls. Splunk employs monitoring and logging technology to help detect and prevent unauthorized access attempts to its networks and production systems. Splunk’s monitoring includes a review of changes affecting systems’ handling authentication, authorization, and auditing; and privileged access to Splunk production systems. Splunk uses the principle of “least privilege” (meaning access denied unless specifically granted) for access to customer data.
Logical Access Controls. Tanium employs the principles of least privilege and need-to-know to control access to Confidential Information and Customer Data. User access privileges are restricted based on business need and job responsibilities, allowing only the minimum necessary access for users to accomplish their job function. User access is revoked upon termination of employment or termination of relevant job duties, and owners of critical applications or systems are required to perform periodic privileged access reviews to ensure access is still required to perform current job duties. In addition, Tanium protects against unauthorized access by ensuring unique user IDs and passwords are in use. Tanium appropriately manages passwords, including enforcing password complexity by (a) requiring a password length of no less than 8 characters, (b) utilizing expiring first-time log-in temporary passwords,
Logical Access Controls. 3.1 Authentication and authorization controls are appropriately robust for the specific levels of risk to the applicable information, data, application, and platform. 3.2 Wherever possible, multi-factor authentication (MFA) is enforced, with FIDO2 protocol being the preferred mechanism, followed by TOTP. 3.3 Access rights are monitored to ensure access adheres to the ‘least privilege’ principle commensurate with the user’s job responsibilities, logs all access and security events, and uses software that enables rapid analysis of user activities. 3.4 User access reviews are performed on a scheduled basis for each application, database, or system housing CyberGRX data to confirm access and privilege levels. 3.5 Procedures are documented for the timely onboarding and off-boarding of users who have joined, left, or changed roles within CyberGRX. 3.6 Remote control of desktop is restricted to a specific role (e.g., helpdesk admin) and remote control is not permitted unless and until the end user gives permission. 3.7 A documented password policy covers all applicable systems, applications, and databases. 3.8 Authorizations must be linked to a unique user ID and account. This excludes the use of group IDs/passwords used by multiple people, with limited exceptions where necessary.
Logical Access Controls. Inovonics will maintain access control policies and to manage what access is allowed to the Services from each network connection and user, including the sue of firewalls or functionally equivalent technology and authentication controls.
Logical Access Controls. (a) Intercom assigns a unique ID to each employee and leverages an Identity Provider to manage access to systems processing Customer Data. (b) All access to systems processing Customer Data is protected by Multi Factor Authentication (MFA). (c) Intercom restricts access to Customer Data to only those people with a “need-to-know” for a Permitted Purpose and following least privileges principles. (d) Intercom regularly reviews at least every 180 days the list of people and systems with access to Customer Data and removes accounts upon termination of employment or a change in job status that results in employees no longer requiring access to Customer Data. (e) Intercom mandates and ensures the use of system-enforced “strong passwords” in accordance with the best practices (described below) on all systems hosting, storing, processing, or that have or control access to Customer Data and will require that all passwords and access credentials are kept confidential and not shared among personnel. 1. Password best practices implemented by Intercom’s Identity Provider. Passwords must meet the following criteria: a. contain at least 10 characters; b. must contain lowercase and uppercase letters, numbers and a special character; c. cannot be part of a vendor provided list of common passwords (f) Intercom maintains and enforces “account lockout” by disabling accounts with access to Customer Data when an account exceeds more than ten (10) consecutive incorrect password attempts. (g) Intercom does not operate any internal corporate network. All access to Intercom resources is protected by strong passwords and MFA. (h) Intercom monitors their production systems and implements and maintains security controls and procedures designed to prevent, detect and respond to identified threats and risks. (i) Strict privacy controls exist in the application code that are designed to ensure data privacy and to prevent one customer from accessing another customer’s data (i.e., logical separation).
Logical Access Controls. Subject to Section 4.1, to the extent you Access Protected Information from Non-Company Systems you will: (i) maintain reasonable access controls to ensure that only individuals who have a legitimate need to access Protected Information under the Agreement will have such access; (ii) promptly terminate an individual’s access to Protected Information when such access is no longer required for performance under the Agreement; (iii) log the appropriate details of access to Protected Information on your systems and equipment, and retain such records for no less than 90 days; and (iv) audit logging of access, plus alarms for attempted access violations, where applicable.
Logical Access Controls. 11.1 Access to Moorepay systems used in the provision of the Services will be granted and revoked in accordance with Logical Access Management Policy, as defined in the Moorepay Security Policy Handbook. 11.2 Passwords allocated will conform to industry standards and align with Password Management Standard in the Moorepay Policy Handbook. 11.3 Authentication and login to Moorepay systems used in the provision of the Services will follow good industry practice. 11.4 System privileges in relation to user IDs will be reviewed regularly in line with controls defined for Moorepay compliance standards and certifications. 11.5 Recording of access and security incidents will be enforced based on good practices and applicable legal requirements. 11.6 Privileged user access, such as system administrators, will be strictly controlled.
Logical Access Controls. All Nuance systems and personal computers are subject to access controls including at least username and password that must meet password complexity requirements and automatic logoff requirements. Data Access Controls: Access to Nuance systems storing Personal Data is granted on a need-to- know basis and is subject to administrator approval. Data at rest is protected either by encryption or compensating security controls, which include segmented networks, tiered architecture, firewalls with intrusion protection and anti-malware protections, and limiting of port access.
Logical Access Controls. IBM will: