A clear desk/clear screen policy reduces the risks of unauthorized access, loss of, and damage to information during and outside normal working hours. Safes or other forms of secure storage facilities might also protect information stored therein against disasters such as a fire, earthquake, flood or explosion. (NL ISO/IEC, 2015) 5. Access Control to Program Source Code Access to program source code and associated items (such as designs, specifications, verification plans and validation plans) should be strictly controlled, in order to prevent the introduction of unauthorized functionality and to avoid unintentional changes as well as to maintain the confidentiality of valuable intellectual property. For program source code, this can be achieved by controlled central storage of such code, preferably in program source libraries. The following guidelines should then be considered to control access to such program source libraries in order to reduce the potential for corruption of computer programs: a) where possible, program source libraries should not be held in operational systems; b) support personnel should not have unrestricted access to program source libraries; c) the updating of program source libraries and associated items and the issuing of program sources to programmers should only be performed after appropriate authorization has been received; d) an audit log should be maintained of all accesses to program source libraries; e) If the program source code is intended to be published, additional controls to help getting assurance on its integrity (e.g. digital signature) should be considered. (NL ISO/IEC, 2015) Lebanese National Security Policy Guidelines v1.7 Page 23 |

Select target paragraph3