UNCLASSIFIED 5.12  Enforce access control measures guided by the least privilege principle to help ensure that no user or application process gains access to accounting and audit data without explicit authorisation and a clearly defined role;  Deny system administrators the access privileges to erase or de-activate logs of their own activities;  Separate accounting and audit logs that support routine security activities from evidential logs that have legal ramifications because they might contain intrusive and confidential personal data and may be admissible in Court;  Ensure that, where protective monitoring activities collect data of relevance in legal proceedings, it is possible to verify and demonstrate the evidential weight of the data and ensure its legal admissibility in Courts of Law;  Have in place a process for escalating to management representatives alerts from real-time accounting and audit systems to enable decisions on whether or not to trigger the incident management process; and  Update the accounting and audit policy to reflect changes in the threat environment and results of technical risk assessments. Information Back-Ups Achieving the mandated minimum information security outcomes outlined below can ensure the integrity and availability of data, software and documentation and enable quick recovery from disasters or media failures. Back-ups should cover all information processing environments such as live and pre-production. IS11 – All organisations must adopt formal policies and procedures to backup and regularly test copies of information and software required to recover from major disruptions. As a minimum requirement, organisations must: (a) define the required back-up levels; (b) base the frequency of back-ups on the value, criticality and sensitivity of data; (c) produce accurate and complete records of back-up copies; (d) store back-up data a safe distance away from the main site; (e) afford back-up information suitable physical and environmental protection; and, (f) test back-up media regularly to ensure its recoverability. To achieve the security outcomes mandated above, organisations must:  Define the extent e.g. full or differential backup and frequency of backups that reflect business requirements as well as security and criticality of the information to the continued operation of the organisation;  Regularly test back-up arrangements for individual information systems to help ensure that they meet the requirements of business continuity plans;  Back-ups for critical systems must cover all systems information, applications and data needed to recover the entire system in the event of a disaster; 34

Select target paragraph3