Accountability and Access
Control
Policies are an important element of access control because they help personnel within the
organization understand what security requirements are important. The security policy is
created or approved by senior leadership, and it provides a broad overview of an organization’s
security needs but usually does not go into details about how to fulfill the needs. For example,
it may state the need to implement and enforce separation of duties and least privilege
principles but not state how to do so. Professionals within the organization use the security
policies as a guide to implement security requirements. Standards are also created from
security policies (Stewart et al., 2004).
1. Purpose
The purpose of this policy is to protect Lebanese government organizations data by controlling
access to IT assets through rules, requirements, and guidelines. The IT assets include, but are
not limited to, systems, networks, media, storage, applications, operating systems, and
databases. The IT assets should fall under the responsibility of the Office of Information
Technology of the organization.
This policy is applicable to all users who have access to the organization data and its IT a ssets.
2. Introduction
Accountability
Authorization
Authentication
Identification
Access Control is the framework for ensuring the safety of IT assets against inadvertent
unauthorized access and appropriately controlling IT assets access. The framework is based on
four pillars, including Identification, Authentication, Authorization and Accountability.
All IT and administrative departments are responsible for developing the relevant Operational
Procedures, Working Instructions, and Technical Documents in line with the rules,
requirements, and guidelines set forth in this policy.
Lebanese National Security Policy Guidelines v1.7
Page
17 |