Objective:
System users comply with information security policies and
procedures within their agency
responsible for all actions under their accounts
Mandatory Control 3:
All system users mustuse their access to only perform authorised
tasks and functions
Mandatory Control 4:
System users that need to bypass security policies, procedures or
mechanisms for any reason must seek formal authorisation from
the CISO or the ITSM, if this authority has been specifically
delegated to the ITSM
If agencies fail to develop and maintain a security culture where system users are complying with
relevant security policies and procedures for the systems they are using, there is an increased
security risk of a system user unwittingly assisting with an attack against a system.
19