Expert Advice Community

Guest

Access profiles

  Quote
Guest
Guest user Created:   Dec 04, 2018 Last commented:   Dec 04, 2018

Access profiles

I would like your guidance as I populate the following tables in the Access Control Policy. Specifically Section No 3. On Access Control.
0 0

Assign topic to the user

ISO 27001 ACCESS CONTROL POLICY

Define the rules for access to various systems.

ISO 27001 ACCESS CONTROL POLICY

Define the rules for access to various systems.

Expert
Rhand Leal Dec 04, 2018

1. User Profile A (which Profiles are expected to be captured here?)
2. User Profile B (which Profiles are expected to be captured here?)

Answer:

As example for profiles you can have Administrator profile (Profile A) and Common user profile (Profile B).

For an operational system you can have the following access rights:
- Administrator: read and write on flies and alter system configurations
- Common user: read and write on flies only

For an corporate networks you can have the following access rights:
- Administrator: remote access to internal networks and full access to Intern
- Common user: internal network access only

This article will provide you further explanation about access control:
- How to handle access control according to ISO 27001 https://advisera.com/27001academy/blog/2015/07/27/how-to-handle-access-control-according-to-iso-27001/

This material will also help you regarding access control:
- ISO 27001 Annex A Controls in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 04, 2018

Dec 04, 2018