System Access Control (Logical Security)

Andrew Chambers, Graham K. Rand · 2012

This chapter examines how access control, known as logical security, is often a key and critical proactive component in the protection of data and systems from unauthorized use. The most common form of access control is the use of a unique user identity and an associated password. Access to application system functionality can be precisely tailored to the specific needs of a user so that unnecessary, sensitive or other areas that are not commensurate with the individual's role can be barred. Risk and control issues for system access control involve examining how management has established a policy of system and data ownership whereby users take responsibility for their systems and data and how management checks that this operation is correctly conducted.

Read the paper · More papers on PaperTik