Business Requirement For Access Control
Business Requirement For Access Control
Business Requirement For Access Control
User Responsibilities
Whether there are any security practice in place
Password use to guide users in selecting and maintaining
secure passwords.
Whether the users and contractors are made
Unattended user aware of the security requirements and
equipment procedures for protecting unattended
equipment. .
Example: Logoff when session is finished or set
up auto log off, terminate sessions when
finished etc.,
Whether the organisation has adopted clear
Clear desk and clear desk policy with regards to papers and
screen policy removable storage media
Whether the organisation has adopted clear
screen policy with regards to information
processing facility