Principle 3: Access and Authorization
James J. DeLuccia IV
Abstract
James J. DeLuccia IV
Abstract
Access and authorization of physical and digital assets for an organization make up the third principle. Universally acknowledged as a necessity in every part of the world, the actual placement and implementation of these types of safeguards can vary greatly, depending on the environment and value of the assets. This chapter highlights technical controls, physical controls, and human resources. Access controls include a reporting and monitoring function that provides intelligence of the activity toward the assets under protection. This information should indicate the account activity, any failed authentication attempts, and the areas in which failures occurred. Organizations must continually support the human resources of the organization and ensure that the entire company is of the same mind and principles with regard to security, compliance, and ethical operations.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Access and authorization of physical and digital assets for an organization make up the third principle. Universally acknowledged as a necessity in every part of the world, the actual placement and implementation of these types of safeguards can vary greatly, depending on the environment and value of the assets. This chapter highlights technical controls, physical controls, and human resources. Access controls include a reporting and monitoring function that provides intelligence of the activity toward the assets under protection. This information should indicate the account activity, any failed authentication attempts, and the areas in which failures occurred. Organizations must continually support the human resources of the organization and ensure that the entire company is of the same mind and principles with regard to security, compliance, and ethical operations.
Key concepts: Authorization, Computer security, Function (biology), Access control, Business, Authentication (law), Compliance (psychology), Value (mathematics)