UNCLASSIFIED 5.6 Access Management Access management focuses on how to control who gains access to critical infrastructure. At its simplest, access management or control aims to ensure that only business and security requirements determine who accesses information, information processing facilities and business processes. Consequently, access control aims to achieve the minimum-security outcomes below. IS5 – Organisations must ensure that only users, processes and devices with a business need and suitable security clearances gain access to critical infrastructure. As a minimum requirement, access management must: (a) follow a formal access control policy linked to HR processes; (b) use formal access registration and revocation processes; (c) require appropriate identification and authentication techniques for all IT systems; (d) enable organisations to deter, detect, resist and defend against accidental or deliberate unauthorised actions; and, (e) enable regular review of access rights. To achieve the security outcomes mandated above, organisations must:  Define and document business requirements for access control and restrict access to critical infrastructure to those who satisfy these requirements;  Adopt an access control policy that enforces the principle of least privilege;  Restrict and control the allocation and use of privileges in accordance with the Need-to-Know principle;  Select and apply a suitable access control model amongst Discretionary, Role Based and Mandatory Access Control;  Apply the principle of uniform access management i.e. use of authentication and authorisation services to control resource use;  Have in place a formal process for user password management;  Ensure that users are aware of and abide by their responsibilities to maintain access controls such as passwords;  Enforce recommendations of access rights reviews e.g. disable users; and  Harden and lockdown user applications such as web browsers and office productivity applications to reduce exposure to software vulnerabilities. 27

Select target paragraph3