4.2 Access Control

Access to information and information processing facilities shall be granted based on business requirements and authorized by management.

  • Implement principle of least privilege
  • Require proper authorization for all access requests
  • Regularly review and update access rights
  • Implement strong authentication mechanisms
Direct URL: