QuestionQ1181

Risk Response and Reporting

An organization follows the principle of least privilege. To help ensure access remains appropriate, application owners should be required to regularly review user access rights by obtaining:

  • A security logs to determine the cause of invalid login attempts.
  • B documentation indicating the intended users of the application.
  • C an access control matrix and approval from the user's manager.
  • D business purpose documentation and software license counts.
Explanation

Periodic access recertification needs an access control matrix to identify each user’s assigned permissions and manager approval to confirm that the access remains necessary for the user’s role and business responsibilities.

Community Discussion

No comments yet. Be the first to start the discussion!