A clear desk/clear screen policy reduces the risks of unauthorized access, loss of, and damage
to information during and outside normal working hours. Safes or other forms of secure storage
facilities might also protect information stored therein against disasters such as a fire,
earthquake, flood or explosion. (NL ISO/IEC, 2015)
5. Access Control to Program Source Code
Access to program source code and associated items (such as designs, specifications,
verification plans and validation plans) should be strictly controlled, in order to prevent the
introduction of unauthorized functionality and to avoid unintentional changes as well as to
maintain the confidentiality of valuable intellectual property. For program source code, this can
be achieved by controlled central storage of such code, preferably in program source libraries.
The following guidelines should then be considered to control access to such program source
libraries in order to reduce the potential for corruption of computer programs:
a) where possible, program source libraries should not be held in operational systems;
b) support personnel should not have unrestricted access to program source libraries;
c) the updating of program source libraries and associated items and the issuing of
program sources to programmers should only be performed after appropriate
authorization has been received;
d) an audit log should be maintained of all accesses to program source libraries;
e) If the program source code is intended to be published, additional controls to help
getting assurance on its integrity (e.g. digital signature) should be considered.
(NL ISO/IEC, 2015)
Lebanese National Security Policy Guidelines v1.7
Page
23 |