UNCLASSIFIED
5.12
Enforce access control measures guided by the least privilege principle to
help ensure that no user or application process gains access to accounting
and audit data without explicit authorisation and a clearly defined role;
Deny system administrators the access privileges to erase or de-activate
logs of their own activities;
Separate accounting and audit logs that support routine security activities
from evidential logs that have legal ramifications because they might contain
intrusive and confidential personal data and may be admissible in Court;
Ensure that, where protective monitoring activities collect data of relevance
in legal proceedings, it is possible to verify and demonstrate the evidential
weight of the data and ensure its legal admissibility in Courts of Law;
Have in place a process for escalating to management representatives alerts
from real-time accounting and audit systems to enable decisions on whether
or not to trigger the incident management process; and
Update the accounting and audit policy to reflect changes in the threat
environment and results of technical risk assessments.
Information Back-Ups
Achieving the mandated minimum information security outcomes outlined below
can ensure the integrity and availability of data, software and documentation and
enable quick recovery from disasters or media failures. Back-ups should cover
all information processing environments such as live and pre-production.
IS11 – All organisations must adopt formal policies and procedures to backup
and regularly test copies of information and software required to recover from
major disruptions. As a minimum requirement, organisations must: (a) define
the required back-up levels; (b) base the frequency of back-ups on the value,
criticality and sensitivity of data; (c) produce accurate and complete records of
back-up copies; (d) store back-up data a safe distance away from the main
site; (e) afford back-up information suitable physical and environmental
protection; and, (f) test back-up media regularly to ensure its recoverability.
To achieve the security outcomes mandated above, organisations must:
Define the extent e.g. full or differential backup and frequency of backups
that reflect business requirements as well as security and criticality of the
information to the continued operation of the organisation;
Regularly test back-up arrangements for individual information systems to
help ensure that they meet the requirements of business continuity plans;
Back-ups for critical systems must cover all systems information, applications
and data needed to recover the entire system in the event of a disaster;
34