Expert Advice Community

Guest

Who should have an OS administrator password?

  Quote
Guest
Guest user Created:   May 03, 2016 Last commented:   May 03, 2016

Who should have an OS administrator password?

Who should have an OS administrator password in a company?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
Antonio Jose Segovia May 03, 2016

Answer:
The best practice, or the standard commonly used, is to use an unique user ID for each employee, because with this way employees are clearly linked with users, and is easy to follow their actions (for example reviewing logs). So, if you have an user that needs to have special privileges to configure an information system (or to access to special resources), this user is the unique person that should have the password of the administrator, because only this user should perform the changes.

By the way, you can define this through a Password Policy, so our template can be interesting for you (you can see a free version clicking on “Free demo” tab) “Password Policy” : https://advisera.com/27001academy/documentation/Password-Policy/

And our online course can be also interesting for you because we give more best practices about information security “ISO 27001:2013 Foundations Course” : https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 03, 2016

May 03, 2016