AM 1. Users will be provided access based on the concept of “least privilege” and governed by a “Need to Know” or a “Need to Have” basis. AM 2. Access will be managed and controlled through system access controls, identification and authentication, and audit trails based on the sensitivity of the information. These request s for access SHALL be authorized by a staff member’s supervisor or manager. AM 3. *Access rights of a user or entity to create, read, update, delete or transmit a Agency’s information assets SHALL be based on a matrix (hierarchical) model of rights defined by business rules established by the owners of that information. AM 4. A process is established which, upon any employee role or status change (including termination), ensures that information system access is updated to reflect the employee’s new role, AM 5. System users that need additional access to bypass security mechanisms for any reason seek formal authorisation from the Security Manager AM 6. *Any unauthorized effort to circumvent the Agency’s access control SHALL be perceived as a security incident, and SHALL be handled in accordance with established incident handling procedure and/or appropriate human resources policies and procedures. AM 7. Audit logs SHALL be enabled and maintained in such a manner as to allow compliance monitoring with government policy and to assist in Incident Management. AM 8. *Logical access to Agency Networks is technically controlled. This MAY be by using Network Admission Control (NAC) services/devices. AM 9. *Secure records are maintained of: a. all authorised system users b. their user identification c. who provided the authorisation to access the system d. when the authorisation was granted e. maintain the record for the life of the system to which access is granted. AM 10. *A logon banner is displayed before access to the system is granted. These banners SHOULD cover: a. access is only permitted to authorised system users b. the system user’s agreement to abide by relevant security policies c. the system user’s awareness of the possibility that system usage is being monitored d. the definition of acceptable use for the system e. legal ramifications of violating the relevant policies. f. Wherever possible requires a system user response, as acknowledgement AM 11. *Centralised authentication repositories such as LDAP, authentication databases, etc. are protected from denial of service attacks and use secure and authenticated channels for retrieval of authentication data. Such repositories SHALL log the following events: a. Unauthorized update/access b. Start and end date and time of activity, together with system identifier c. User identification (for illegal logon) d. Sign-on and sign-off activity (for illegal logon) e. Session/terminal or remote connection 9.3. Policy & Baseline Controls – Identification & Authentication In order to comply with this policy, Agencies MUST ensure: AM 12. 41 They develop and maintain a set of policies, plans and procedures, derived from the National NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3