Page 4.2 4.3 4.4 Operating Systems 4 - 2 4.2.1 Proprietary Issues 4 - 3 4.2.2 Shareware and Freeware Operating System Issues 4 - 3 4.2.3 Logical Access Control 4 - 3 4.2.3.1 Identification of Users 4 - 3 4.2.3.2 Authentication of Users 4 - 4 4.2.3.3 Limiting log-on Attempts 4 - 5 4.2.3.4 Unattended Terminals 4 - 6 4.2.3.5 Warning Messages 4 - 6 4.2.4 Audit Trails 4 - 6 4.2.5 Back-up 4 - 7 4.2.6 Maintenance 4 - 7 4.2.6.1 Patches and Vulnerabilities 4 - 7 4.2.6.2 Upgrades 4 - 7 Application System 4 - 8 4.3.1 Application Software 4 - 8 4.3.2 Databases 4 - 8 4.3.3 Systems which Employ Artificial Intelligence 4 - 9 4.3.4 Application Testing 4 - 9 4.3.5 Defective and Malicious Software 4 - 9 4.3.6 Change of Versions 4 - 10 4.3.7 Availability of Source Code 4 - 10 4.3.8 Unlicensed Software 4 - 10 4.3.9 Intellectual Property Rights 4 - 11 4.3.10 Malicious Code 4 - 11 4.3.11 Unauthorised Memory Resident Programs 4 - 11 4.3.12 Software Provided to External Parties 4 - 12 4.3.13 Software from External Sources 4 - 12 Network System 4 - 13 4.4.1 Securing a Network 4 - 13 4.4.1.1 Design of a Secure Network 4 - 13 4.4.1.2 Network Security Controls 4 - 14 4.4.2 Security of Network Equipment 4 - 15 4.4.2.1 Installation Security 4 - 15 4.4.2.2 Physical Security 4 - 15 4.4.2.3 Physical Access 4 - 16 x

Select target paragraph3