0% found this document useful (0 votes)
12 views23 pages

Access Control & User Management Guide

Uploaded by

Cj Nibir Sarker
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views23 pages

Access Control & User Management Guide

Uploaded by

Cj Nibir Sarker
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Access Control and User

Management

Access Control and


User Management

Nibir Sarker
SO-IT
IT Procurement , Security ,
Compliance & Maintenance Dept.
Access Control and User
Management
Key
Points
Access Control

Types of Access Control

Key Components of Access Control:

Password Policy

Password Duration & Strength

Physical Security
Access Control and User
Management

Access Control

Access Controls should provide reasonable assurance that data


and applications are protected against unauthorized
modifications, disclosure, loss or impairment. Such controls
include physical controls, such as keeping a computer in a locked
room to limit physical access, and logical controls such as
security software programs designed to prevent or detect
unauthorized access to sensitive files.
Access Control and User
Management

Data Access Control

Data access control is a technique


Network

used to regulate employees access


Operating
to files in an organization. It’s System

typically refers to software and Application


Software
activities related to storing, (CBS)

retrieving, or acting on data housed


in a database. Data Access is simply Data

the authorization you have to access


different data files.
Access Control and User
Management

Types of Access Control

Discretionary Access Control (DAC):

Mandatory Access Control (MAC):

Role-Based Access Control (RBAC):


Access Control and User
Management

Discretionary Access Control (DAC):

Discretionary Access Control is a decentralized access control policy that


allows subjects to control access to objects. You can find DAC in
smartphone apps, Google Docs, and Operating Systems worldwide. In
DAC systems, subjects can share information with other users. They can
grant privileges to others.
Access Control and User
Management

Mandatory Access Control (MAC):

Mandatory access control is a centralized access control


system. MAC regulates access to resources based on the
clearance levels of users and the attributes of objects they
seek to access.
Access Control and User
Management
Role-Based Access Control (RBAC):
Role-based access control (RBAC) is a model for authorizing
end-user access to systems, applications and data based on a
user’s predefined role. For example, a security analyst can
configure a firewall but can’t view customer data, while a sales
rep can see customer accounts but can’t touch firewall
settings.
Access Control and User
Management
Key Components of Access Control:

Identification

Authentication

Authorization

Accountability (Auditing)
Access Control and User
Management

Identification:
Identification in access control refers to the process where a
user, system, or entity claims an identity to access
resources. This step typically comes before authentication
and is the first part of the access control process.
Identification is crucial because it establishes the basis for
granting or denying access based on predefined policies or
roles.
Access Control and User
Management

Authentication

What is Authentication?
Authentication is the process of identifying users that request
access to a system, or a part of a system. Access control often
determines user identity according to credentials such as Face
Recognition, Fingerprint, PIN, Password, etc. Other authentication
technologies like authentication apps, QR codes, and Bluetooth are
also used to authenticate user identity
Access Control and User
Management

Authentication
Methods

We can authenticate an identity in three ways:


 Something the user knows (such as a password or personal
identification number/ PIN)
 Something the user has (a security token or smart card)
 Something the user is (a physical characteristic, such as a fingerprint,
called a biometric).
Access Control and User
Management

Authorizatio
n
Authorization in access control refers to the process of
granting or denying access to a resource after the identity of
a user or entity has been verified (through authentication).
Once a user's identity is established, authorization
determines whether they have permission to access specific
resources or perform certain actions based on predefined
access control policies.
Access Control and User
Management

Accountability (Auditing):

Tracking and recording access events to ensure compliance


and detect unauthorized activities.
Access Control and User
Management

Password Policy

A password policy is a set of rules designed to enhance

computer security by encouraging users to employ strong

passwords and use them properly.

A password policy is often part of an organization's official

regulations and may be taught as part of security awareness

training. The password policy may either be advisory or

mandated by technical means.


Access Control and User
Management
Password Management of JBL ICT Security Policy
• The allocation of passwords shall be formally controlled. User
password responsibilities shall be documented in their signed User
Management Form.

• Users shall be initially issued a temporary password which must be


changed at first login. Password should be in good format i.e. should
not contain common passwords like own/spouse/children name, cell
phone number, Birth year, jbl123, pass123, abc123, 1234,123456
etc.

• Users shall always change password in a manner to avoid shoulder


surfing.

• Users shall not share password with anyone and write password on
sticky notes/paper and store in their PC.

• All passwords shall be changed at least every 30 days.


Access Control and User
Management

Password Management of JBL ICT Security Policy


• A User cannot submit a new password that is the same as any of the
last 3 passwords he/she has used.

• Passwords shall be between 8‐12 characters in length; containing a


combination of upper/lower case alphabets, numerals and special
characters i.e. (~!@#$%^&*+).

• Passwords must be changed immediately if it is suspected to be


compromised and reported to CISO/ GM- ICT.

• All Administrative passwords (OS, IOS, Core Banking Solution, DBMS


etc.) shall be locked and must be kept in sealed envelope and stored
in a safe custody.
• The default passwords on all new equipment shall be changed to
conform to the Bank’s password requirements before the equipment
is brought into service.
Access Control and User
Management

Password Management of JBL ICT Security Policy

• Passwords must be rendered unreadable during transmission and


storage on all system components using strong cryptography.

• Password reset requests must be initiated through the Bank’s user


access workflow (confirmation from supervisor or written evidence)
and cannot be initiated by telephone.

• User should never use the "Remember Password" feature in any


application or web sites.

• Login information should not be e-mailed through public channel.


Access Control and User
Management

Password Cracking
Access Control and User
Management

Physical Security

Physical security refers to the protection of people, property,


hardware, software, networks, and data from physical actions or
events that could cause serious loss or damage. This includes
protection from natural disasters, theft, vandalism, terrorism, and
accidental damage.
Access Control and User
Management
Physical Security for Desktop and Laptop
Computers
• Desktop computer shall be connected to UPS.
• Before leaving a desktop or laptop computer unattended, users shall
apply the "Lock Workstation" feature.
• Password protected screen saver shall be used.
• Laptop computers that store confidential or sensitive information must
have encryption technology.
• Desktop and laptop computers and monitors shall be turned off at the
end of each workday.
• Any kind of viruses shall be reported immediately.
• Viruses shall not be deleted without expert assistance unless otherwise
instructed.
• ID and password shall be required to access all desktops and laptops
whenever turned on or restarted.
• All computers shall be placed above the floor level and away from
windows.
Access Control and User
Management
Access Control and User
Management

???
Thank You

You might also like