Source |
The State of Security |
Identifiant |
8640047 |
Date de publication |
2025-01-20 03:32:56 (vue: 2025-01-20 10:08:29) |
Titre |
CIS Control 06: Access Control Management |
Texte |
CIS Control 6 merges some aspects of CIS Control 4 (admin privileges) and CIS Control 14 (access on a need-to-know basis) into a single access control management group. Access control management is a critical component in maintaining information and system security, restricting access to assets based on role and need. It is important to grant, refuse, and remove access in a standardized, timely, and repeatable way across an entire organization. Privileged accounts, such as administrators, should be protected with multi-factor authentication. Enforcing and maintaining access control policies...
CIS Control 6 merges some aspects of CIS Control 4 (admin privileges) and CIS Control 14 (access on a need-to-know basis) into a single access control management group. Access control management is a critical component in maintaining information and system security, restricting access to assets based on role and need. It is important to grant, refuse, and remove access in a standardized, timely, and repeatable way across an entire organization. Privileged accounts, such as administrators, should be protected with multi-factor authentication. Enforcing and maintaining access control policies... |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
06: access accounts across admin administrators aspects assets authentication based basis cis component control critical enforcing entire factor grant group important information know maintaining management merges multi need organization policies privileged privileges protected refuse remove repeatable restricting role security should single some standardized such system timely way |
Tags |
|
Stories |
|
Move |
|