UNCLASSIFIED
5.6
Access Management
Access management focuses on how to control who gains access to critical
infrastructure. At its simplest, access management or control aims to ensure that
only business and security requirements determine who accesses information,
information processing facilities and business processes. Consequently, access
control aims to achieve the minimum-security outcomes below.
IS5 – Organisations must ensure that only users, processes and devices with a
business need and suitable security clearances gain access to critical
infrastructure. As a minimum requirement, access management must: (a)
follow a formal access control policy linked to HR processes; (b) use formal
access registration and revocation processes; (c) require appropriate
identification and authentication techniques for all IT systems; (d) enable
organisations to deter, detect, resist and defend against accidental or
deliberate unauthorised actions; and, (e) enable regular review of access
rights.
To achieve the security outcomes mandated above, organisations must:
Define and document business requirements for access control and restrict
access to critical infrastructure to those who satisfy these requirements;
Adopt an access control policy that enforces the principle of least privilege;
Restrict and control the allocation and use of privileges in accordance with
the Need-to-Know principle;
Select and apply a suitable access control model amongst Discretionary,
Role Based and Mandatory Access Control;
Apply the principle of uniform access management i.e. use of authentication
and authorisation services to control resource use;
Have in place a formal process for user password management;
Ensure that users are aware of and abide by their responsibilities to maintain
access controls such as passwords;
Enforce recommendations of access rights reviews e.g. disable users; and
Harden and lockdown user applications such as web browsers and office
productivity applications to reduce exposure to software vulnerabilities.
27