11.11

From Corrective Action Plan AZ

Control Activities

Principle 11 - Design General Control Activities over Information Technology

Attribute 11.11 - Logical and physical access control activities include restricting access or detecting inappropriate access to information and information technology. They protect information technology resources against unauthorized access, use, disclosure, disruption, modification, or destruction, whether from malicious intent or error. Logical access control activities require users to authenticate themselves and restrict them to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management may grant different permissions to employees and end users, including the rights to create, read, edit, or delete a file; execute a program; and retrieve or update information in a database. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. Physical access control activities involve restricting physical access to information and information technology, including the physical infrastructure, and protecting it from intentional or unintentional loss or impairment.

>>>Navigational Buttons<<<


No Examples