It’s important to realize that just because users or other entities can authenticate to a
system, that doesn’t mean they are given access to anything and everything. Instead,
subjects are authorized access to specific objects based on their proven identity. The
process of authorization ensures that the requested activity or object access is possible
based on the privileges assigned to the subject. (Stewart et al., 2004)
Accountability
Accountability, which is done via auditing, logging, and monitoring, ensures that
subjects can be held accountable for their actions. Auditing is the process of tracking
and recording subject activities within logs. Logs typically record who took an action,
when and where the action was taken, and what the action was. One or more logs
create an audit trail that can be used to reconstruct events and to verify whether a
security policy or authorization was violated. When contents of audit trails are
reviewed, people associated with the accounts can be held accountable for their
actions. Accountability relies on effective identification and authentication, but it does
not require effective authorization. In other words, if users are adequately identified
and authenticated, accountability mechanisms such as audit logs can track their activity,
even when they access resources they shouldn’t. (Stewart et al., 2004)
3. User Access Management
3.1. User Registration
There should be a formal user registration and de-registration procedure in place for granting
and revoking access to all information systems and services . (NL ISO/IEC, 2010)
The access control procedure for user registration and de-registration should be clear and
contain all the necessary steps and details in order to comply with the policy procedures.
3.2. Privilege Management
The allocation and use of privileges should be restricted and controlled. Multi -user systems that
require protection against unauthorized access should have the allocation of privileges
controlled through a formal authorization process.
Inappropriate use of system administration privileges (any feature or facility of an information
system that enables the user to override system or application controls) can be a major
contributory factor to the failures or breaches of systems. (NL ISO/IEC, 2010)
3.3. User Password Management
The allocation of passwords should be controlled through a formal management process.
The process should include the following requirements:
Lebanese National Security Policy Guidelines v1.7
Page
19 |