HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual S 2.31 Documentation on Authorised Users and on Rights Profiles

S 2.31 Documentation on Authorised Users and on Rights Profiles

Initiation responsibility: Head of IT Section, IT Security Management

Implementation responsibility: Administrator

Such documentation serves to provide an overview of the authorised users, user groups and rights profiles and is required for effective monitoring.

The following three means of providing documentation should all be used:

In particular, the following should be documented:

The documentation regarding the authorised users and rights profiles should be checked at regular intervals (at least every six months) to see whether it reflects the actual situation regarding the granting of rights and whether the assignment of rights still matches the security requirements and the current tasks of the users.

Additional controls:


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
last update:
October 2000
home