Castleforce IT Security Team

A.11.3 User responsibilities

Objective: To prevent unauthorized user access, and compromise or theft of information and information processing facilities.

A.11.3.1 Password use

Control

Users shall be required to follow good security practices in the selection and use of passwords.

A.11.3.2 Unattended user equipment

Control

Users shall ensure that unattended equipment has appropriate protection.

A.11.3.3 Clear desk and clear screen policy

Control

A clear desk policy for papers and removable storage media and a clear screen policy for information processing facilities shall be adopted.

Contact Castleforce for help with ISO27001