What to Provide
Access Control policy for all in-scope production systems.
Evidence Format
Document(s) in a common document file type such as .pdf or .doc.
Additional Guidance
Your Access Control policy is typically covered by your Information Security Policy.
You should cover the following areas in the policy:
Adding new users
Modifying existing user's access
Removing an existing user's access and terminating a user
Restricting access based on separation of duties and least privilege
Associated Unified Control ID | Associated Framework Control |
CTRL-1 | LCL-24 |