Page
4.2
4.3
4.4
Operating Systems
4 - 2
4.2.1
Proprietary Issues
4 - 3
4.2.2
Shareware and Freeware Operating System Issues
4 - 3
4.2.3
Logical Access Control
4 - 3
4.2.3.1
Identification of Users
4 - 3
4.2.3.2
Authentication of Users
4 - 4
4.2.3.3
Limiting log-on Attempts
4 - 5
4.2.3.4
Unattended Terminals
4 - 6
4.2.3.5
Warning Messages
4 - 6
4.2.4
Audit Trails
4 - 6
4.2.5
Back-up
4 - 7
4.2.6
Maintenance
4 - 7
4.2.6.1
Patches and Vulnerabilities
4 - 7
4.2.6.2
Upgrades
4 - 7
Application System
4 - 8
4.3.1
Application Software
4 - 8
4.3.2
Databases
4 - 8
4.3.3
Systems which Employ Artificial Intelligence
4 - 9
4.3.4
Application Testing
4 - 9
4.3.5
Defective and Malicious Software
4 - 9
4.3.6
Change of Versions
4 - 10
4.3.7
Availability of Source Code
4 - 10
4.3.8
Unlicensed Software
4 - 10
4.3.9
Intellectual Property Rights
4 - 11
4.3.10
Malicious Code
4 - 11
4.3.11
Unauthorised Memory Resident Programs
4 - 11
4.3.12
Software Provided to External Parties
4 - 12
4.3.13
Software from External Sources
4 - 12
Network System
4 - 13
4.4.1
Securing a Network
4 - 13
4.4.1.1
Design of a Secure Network
4 - 13
4.4.1.2
Network Security Controls
4 - 14
4.4.2
Security of Network Equipment
4 - 15
4.4.2.1
Installation Security
4 - 15
4.4.2.2
Physical Security
4 - 15
4.4.2.3
Physical Access
4 - 16
x