Skip to main content

ER-28 Pre-Kickoff - Access Control Policy

C
Written by Claudio Morsella
Updated over a month ago

Access Control Policy

Provide your Access Control policy for all in-scope production systems.

Additional Guidance
Your Access Control policy is typically covered by your Information Security Policy.

You should cover the following areas in the policy:

  • Adding new users

  • Modifying existing user's access

  • Removing an existing user's access and terminating a user

  • Restricting access based on separation of duties and least privilege

Associated Unified Control ID

Associated Framework Control

CTRL-1

LCL-24

Did this answer your question?