Hello, where is my question inside the Access Control Policy: chapter 3.4 Management of special rights
Question: The business and security requirements for access are defined in the „Directory for Risk Assessment“(?) I don’t understand this. Can you explain that connection to me, please?
Please note that the original English text is "When allocating privileges the person responsible must take into account business and security requirements for access (defined in risk assessment), ..."
Considering this text, business and security requirements for access are not defined in the risk assessment. The risk assessment only provides additional information that must be considered when defining such accesses. An example of business requirement for access is remote access to some roles (e.g., sales staff, remote developers, etc.)