Accountability and Access Control Policies are an important element of access control because they help personnel within the organization understand what security requirements are important. The security policy is created or approved by senior leadership, and it provides a broad overview of an organization’s security needs but usually does not go into details about how to fulfill the needs. For example, it may state the need to implement and enforce separation of duties and least privilege principles but not state how to do so. Professionals within the organization use the security policies as a guide to implement security requirements. Standards are also created from security policies (Stewart et al., 2004). 1. Purpose The purpose of this policy is to protect Lebanese government organizations data by controlling access to IT assets through rules, requirements, and guidelines. The IT assets include, but are not limited to, systems, networks, media, storage, applications, operating systems, and databases. The IT assets should fall under the responsibility of the Office of Information Technology of the organization. This policy is applicable to all users who have access to the organization data and its IT a ssets. 2. Introduction Accountability Authorization Authentication Identification Access Control is the framework for ensuring the safety of IT assets against inadvertent unauthorized access and appropriately controlling IT assets access. The framework is based on four pillars, including Identification, Authentication, Authorization and Accountability. All IT and administrative departments are responsible for developing the relevant Operational Procedures, Working Instructions, and Technical Documents in line with the rules, requirements, and guidelines set forth in this policy. Lebanese National Security Policy Guidelines v1.7 Page 17 |

Select target paragraph3