ISO IEC 17799 2000TRANSLATED INTO PLAIN ENGLISHSection 9: Access ControlFREE DETAILED STANDARD |
||
| MAIN MENU | TO SECTION 10 | |
|
ISO
17799 2000 is now OBSOLETE. |
||
![]()
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
9.1 CONTROL ACCESS TO INFORMATION |
|
|
|
Make sure that your information access |
|
|
Make sure that your information access |
|
|
Make sure that your information access
controls |
|
|
Make sure that your information access
controls |
|
9.1.1 DEVELOP A POLICY AND RULES TO CONTROL ACCESS |
|
|
9.1.1.1 DEVELOP A POLICY TO CONTROL INFORMATION ACCESS |
|
|
|
Define and document the business requirements
|
|
|
Make sure that
your users understand the business |
|
|
Make sure that
your service providers understand the |
|
|
Develop a policy to control information access. |
|
|
Make sure that
your access control policy |
|
|
Make sure that
your access control policy defines the rules |
|
|
Make sure that
access control policy defines the security |
|
|
Make sure that access control policy defines how information dissemination and authorization should be controlled. |
|
|
Make sure that
your access control policy complies |
|
|
Make sure that your
access control policy meets all
|
|
|
Make sure that
access control policy allows the use of |
|
|
Make sure that your access control policy
supports |
|
|
Make sure that
your access control policy recognizes |
|
|
Make sure that
your information access control policy |
|
9.1.1.2 DEVELOP INFORMATION ACCESS CONTROL RULES |
|
|
|
Develop rules to control access to information. |
|
|
Make sure that
your access control rules specify |
|
|
Make sure that
access control rules forbid access except |
|
|
Make sure that
access control rules distinguish between |
|
|
Make sure that
access control rules distinguish between |
|
|
Make sure that
you distinguish between user access |
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
9.2 MANAGE THE ALLOCATION OF ACCESS RIGHTS |
|
|
|
Establish a procedure to control the
allocation of |
|
|
Ensure that your access rights allocation
procedure controls |
|
|
Ensure that your access rights allocation procedure pays
|
|
9.2.1 ESTABLISH A USER REGISTRATION PROCEDURE |
|
|
|
Develop a formal procedure to control the
registration |
|
|
Make sure that
your user registration procedure |
|
|
Make sure that
your user registration |
|
|
Make sure that
your user registration procedure ensures that |
|
|
Make sure that your user registration procedure specifies when management authorization is required before user access is granted. |
|
|
Make sure that
your user registration procedure ensures that the |
|
|
Make sure that
your user registration procedure ensures that |
|
|
Make sure that
your user registration procedure ensures that the |
|
|
Make sure that
your user registration procedure ensures that users |
|
|
Make sure that
your registration procedure ensures that all users |
|
|
Make sure that
your user registration procedure ensures that |
|
|
Make sure that
your user registration procedure ensures |
|
|
Make sure that
your user registration procedure ensures |
|
|
Make sure that
your user registration procedure ensures |
|
|
Make sure that
your user registration procedure ensures |
|
|
Make sure that
your employment contracts specify the |
|
|
Make sure that
your service contracts specify the sanctions |
|
9.2.2 CONTROL THE AUTHORIZATION OF SYSTEM PRIVILEGES |
|
|
|
Establish a formal authorization process
that must be used |
|
|
Specify exactly what the special privileges
should |
|
|
Specify which staff members should have which
|
|
|
Grant system privileges only when they are needed. |
|
|
Make sure that your authorization process ensures that system privileges are not granted until all formal authorization steps have been completed. |
|
|
Maintain a record of all privilege allocations. |
|
|
Reduce the need to grant privileges by
promoting |
|
|
Ensure that the same user identity is not used
to grant |
|
9.2.3 ESTABLISH A PROCESS TO MANAGE PASSWORDS |
|
|
|
Establish a formal process to manage and
control |
|
|
Make sure that your password management
process ensures |
|
|
Make sure that your password management
process ensures that |
|
|
Make sure that your password management
process ensures |
|
|
Make sure that your password management
process ensures |
|
|
Make sure that your password management
process ensures |
|
|
Make sure that your password management
process ensures |
|
|
Store passwords on a secure computer system. |
|
9.2.4 REVIEW USER ACCESS RIGHTS AND PRIVILEGES |
|
|
|
Make sure that managers review user access rights and privileges. |
|
|
Make sure that user access rights are reviewed on a regular basis. |
|
|
Make sure that access rights are reviewed whenever changes occur. |
|
|
Make sure that access privileges are reviewed more often than rights. |
|
|
Make sure that access privileges are reviewed on a regular basis. |
|
|
Make sure that access privileges are reviewed
in order to |
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
9.3 ENCOURAGE RESPONSIBLE ACCESS PRACTICES |
|
|
|
Ask authorized users to help you control
access to |
|
|
Make authorized users responsible for helping
you |
|
|
Make users aware of what they must do to control access. |
|
|
Make users aware of what they must do to protect passwords. |
|
|
Make users aware of what they must do to protect equipment. |
|
9.3.1 ENCOURAGE USERS TO PROTECT PASSWORDS |
|
|
|
Make sure that your users follow best
information |
|
|
Make sure that your users select passwords |
|
|
Make sure that users select passwords |
|
|
Make sure that users select passwords |
|
|
Make sure that users avoid selecting passwords
|
|
|
Make sure that your users follow best
information |
|
|
Make sure that users protect the |
|
|
Make sure that your users ensure that all
written |
|
|
Make sure that
users change passwords whenever the security |
|
|
Make sure that users change passwords on a regular basis. |
|
|
Make sure that users avoid using previously used passwords. |
|
|
Make sure that users change passwords more often for
|
|
|
Make sure that your users change |
|
|
Make sure that your users ensure that
passwords are not |
|
|
Make sure that users avoid sharing passwords with others. |
|
|
Make sure that users are formally authorized
to use a single password |
|
9.3.2 ENCOURAGE USERS TO PROTECT EQUIPMENT |
|
|
|
Make sure that users know how to protect unattended equipment. |
|
|
Make sure that users understand the security
requirements |
|
|
Make sure that users understand the security
procedures |
|
|
Make sure that your users understand what
their |
|
|
Make sure that your users protect their |
|
|
Make sure that your contractors know |
|
|
Make sure that contractors understand |
|
|
Make sure that your contractors understand |
|
|
Make sure that your contractors know what
their |
|
|
Make sure that your contractors protect |
|
|
Make sure that users are told to secure their
equipment or |
|
|
Make sure that users are told to log‑off
mainframe |
|
|
Make sure that users are told to protect
terminals or PCs |
|
|
Make sure that workstations and file servers
are given special |
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
9.4 CONTROL ACCESS TO COMPUTER NETWORKS |
|
|
|
Control access to internal networked services. |
|
|
Control access to external networked services. |
|
|
Control access by using the appropriate
interfaces between |
|
|
Control access by using the appropriate
interfaces |
|
|
Control access to networks by using the appropriate
|
|
|
Control user access to information services. |
|
9.4.1 FORMULATE A NETWORK USE POLICY |
|
|
|
Establish a policy to control the use of networks and network services. |
|
|
Make sure that your network use policy ensures
that users are |
|
|
Make sure that your network use policy ensures
that users are |
|
|
Make sure that your network use policy ensures
that users are |
|
|
Make sure that your network use policy
identifies the networks |
|
|
Make sure that your network use policy
establishes procedures that |
|
|
Make sure that your network use policy
establishes management |
|
|
Make sure that your network use policy
establishes management |
|
|
Make sure that your network use policy is
consistent |
|
9.4.2 USE ENFORCED PATHS TO CONTROL ACCESS |
|
|
|
Reduce the opportunity for unauthorized access to business applications by controlling the path from the user terminal to the computer service. |
|
|
Reduce the opportunity for unauthorized use of
information facilities |
|
|
Establish controls to restrict the route
between user terminals |
|
|
Make sure that your path controls prevent
users from |
|
|
Limit the users routing options by allocating
|
|
|
Limit the users routing options by
automatically |