Oh no! No description found. But not to worry. Read from Tasks below how to advance this topic.
Establish a formal process for administration of accounts, access rights and privileges. a) The process should cover i) accounts for users, devices and system processes, ii) access rights to systems and applications, iii) privileges in relation to operating systems (e.g. admin privileges) and the organisation’s shared user database. b) The process should include the entire life cycle and cover creation, maintenance and deactivation. Deactivate rather than delete accounts and access rights in order that there is an audit trail in accordance with prevailing laws and regulations. c) The guidelines on access control (2.6.1) and the process for administering accounts, access rights and privileges (2.6.2.a) should be documented and communicated across the organisation.
Establish a formal process for administration of accounts, access rights and privileges. a) The process should cover i) accounts for users, devices and system processes, ii) access rights to systems and applications, iii) privileges in relation to operating systems (e.g. admin privileges) and the organisation’s shared user database. b) The process should include the entire life cycle and cover creation, maintenance and deactivation. Deactivate rather than delete accounts and access rights in order that there is an audit trail in accordance with prevailing laws and regulations. c) The guidelines on access control (2.6.1) and the process for administering accounts, access rights and privileges (2.6.2.a) should be documented and communicated across the organisation.
In Cyberday, requirements and controls are mapped to universal tasks. A set of tasks in the same topic create a Policy, such as this one.
In Cyberday, requirements and controls are mapped to universal tasks. Each requirement is fulfilled with one or multiple tasks.
When building an ISMS, it's important to understand the different levels of information hierarchy. Here's how Cyberday is structured.
Sets the overall compliance standard or regulation your organization needs to follow.
Break down the framework into specific obligations that must be met.
Concrete actions and activities your team carries out to satisfy each requirement.
Documented rules and practices that are created and maintained as a result of completing tasks.