12.2.
Authorizations and Briefings
Objective:
Mandatory Control 1:
Mandatory Control 2:
Recommended Control 1:
Recommended Control 2:
Only appropriately authorized, cleared and briefed personnel are
allowed access to systems
Agencies must specify in the System Security Plan (SecPlan) any
authorisations and briefings necessary for system access
Where systems process, store or communicate unprotected GOB
information, agencies must not allow foreign nationals, including
seconded foreign nationals, to have access to the system
Agencies should:
limit system access on a need‐to‐know/need to access basis
provide system users with the least amount of privileges
needed to undertake their duties
have any requests for access to a system authorized by the
supervisor or manager of the system user
Agencies should maintain a secure record of:
all authorized system users
their user identification
why access is required
role and privilege level
who provided the authorization to access the system
when the authorization was granted
maintain the record, for the life of the system or the length
of employment whichever is the longer, to which access is
granted
Ensuring that the requirements for access to a system are documented and agreed upon will assist
in determining if system users have appropriate authorizations and need‐to‐know to access the
system. Access requirements that will need to be documented include general users, privileged
users, systems administrators, contractors and visitors.
Personnel seeking access to a system will need to have a genuine business requirement to access
the system as verified by their supervisor or manager. Once a requirement to access a system is
established, the system user should be given only the privileges that they need to undertake their
duties. Providing all system users with privileged access when there is no such requirement can
cause significant security vulnerabilities in a system.
In many cases, the requirement to maintain a secure record of all personnel authorized to access a
system, their user identification, who provided the authorization and when the authorization was
granted, can be met by retaining a completed system account request form signed by the
supervisor or manager of the system user.
53