
Control
Access to operating systems shall be controlled by a secure log-on procedure.
Control
All users shall have a unique identifier (user ID) for their personal use only, and a suitable authentication technique shall be chosen to substantiate the claimed identity of a user.
Control
Systems for managing passwords shall be interactive and shall ensure quality passwords.
Control
The use of utility programs that might be capable of overriding system and application controls shall be restricted and tightly controlled.
Control
Inactive sessions shall shut down after a defined period of inactivity.
Control
Restrictions on connection times shall be used to provide additional security for high-risk applications.
© Copyright Castleforce 2007-2012. Web design by Theme Group