12.2. Authorizations and Briefings Objective: Mandatory Control 1: Mandatory Control 2: Recommended Control 1: Recommended Control 2: Only appropriately authorized, cleared and briefed personnel are allowed access to systems Agencies must specify in the System Security Plan (SecPlan) any authorisations and briefings necessary for system access Where systems process, store or communicate unprotected GOB information, agencies must not allow foreign nationals, including seconded foreign nationals, to have access to the system Agencies should: limit system access on a need‐to‐know/need to access basis provide system users with the least amount of privileges needed to undertake their duties have any requests for access to a system authorized by the supervisor or manager of the system user Agencies should maintain a secure record of: all authorized system users their user identification why access is required role and privilege level who provided the authorization to access the system when the authorization was granted maintain the record, for the life of the system or the length of employment whichever is the longer, to which access is granted Ensuring that the requirements for access to a system are documented and agreed upon will assist in determining if system users have appropriate authorizations and need‐to‐know to access the system. Access requirements that will need to be documented include general users, privileged users, systems administrators, contractors and visitors. Personnel seeking access to a system will need to have a genuine business requirement to access the system as verified by their supervisor or manager. Once a requirement to access a system is established, the system user should be given only the privileges that they need to undertake their duties. Providing all system users with privileged access when there is no such requirement can cause significant security vulnerabilities in a system. In many cases, the requirement to maintain a secure record of all personnel authorized to access a system, their user identification, who provided the authorization and when the authorization was granted, can be met by retaining a completed system account request form signed by the supervisor or manager of the system user. 53

Select target paragraph3