|
An Introduction To |
|
Application and information access controlObjective: To prevent unauthorised access to information held in application systems. Logical access controls should be used to control access to application systems and information. Information access restrictionAccess to information and applications should be granted in accordance with the business access control policy. Sensitive system isolationWhere appropriate, sensitive systems should have their own isolated operating environment. |
The Security Practitioner An Introduction to Information Security |