11.11

From Arizona Citizen Voice

Control Activities

Principle 11 - Design General Control Activities over Information Technology

Attribute 11.11 - Logical and physical access control activities include restricting access or detecting inappropriate access to information and information technology. They protect information technology resources against unauthorized access, use, disclosure, disruption, modification, or destruction, whether from malicious intent or error. Logical access control activities require users to authenticate themselves and restrict them to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management may grant different permissions to employees and end users, including the rights to create, read, edit, or delete a file; execute a program; and retrieve or update information in a database. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. Physical access control activities involve restricting physical access to information and information technology, including the physical infrastructure, and protecting it from intentional or unintentional loss or impairment.

>>>Navigational Buttons<<<


Jamie's Story

No examples are available to illustrate governance gaps for this attribute.

Election Anomalies

Arizona Senate Allegations

Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the Arizona Attorney General's Office 2020 General Election Investigation. This Green Book attribute applies given the Arizona Senate's concern that the 2020 election results may have been fraudulently reported,