HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual S 2.65 Checking the efficiency of User separation on an IT System

S 2.65 Checking the efficiency of User separation on an IT System

Initiation responsibility: Head of IT Section, IT Security Management

Implementation responsibility: Auditor, Administrator, IT Security Management

By means of report assessment or random testing, it should be checked at appropriate intervals whether the users of the IT system log-off regularly after finishing their task or whether several users work under one ID.

Should it be found that several users work under one ID, then they should be made aware of the duty of logging off after a task is finished. At the same time, it should be pointed out that this is in the interest of the user.

Should it also be determined that the log-on and log-off processes take too much time and are not accepted despite a request to do so, alternative measures should be discussed, such as:

Additional controls:


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
July 1999
home