|
An Introduction To |
|
Operating system access controlObjective: To prevent unauthorised access to operating systems. Access to the operating system should be controlled. Secure log-on proceduresAccess to operating systems should be controlled via a secure log-on process. User identification and authenticationAll users should have an unique identifier for their personal use so that all activities can be traceable to responsible individuals. A suitable authentication technology (or technologies) should be in place to substantiate the claimed identity. Password management systemAn effective password system should be used to authenticate users. Use of system utilitiesThe use of system utilities must be restricted and tightly controlled. Session time-outSessions should be set to time out to prevent access by unauthorised persons. Limitation of connection timeRestrictions of connection times should provide additional security for high-risk applications. |
The Security Practitioner An Introduction to Information Security |