Access Control and User
Management
Access Control and
User Management
Nibir Sarker
SO-IT
IT Procurement , Security ,
Compliance & Maintenance Dept.
Access Control and User
Management
Key
Points
Access Control
Types of Access Control
Key Components of Access Control:
Password Policy
Password Duration & Strength
Physical Security
Access Control and User
Management
Access Control
Access Controls should provide reasonable assurance that data
and applications are protected against unauthorized
modifications, disclosure, loss or impairment. Such controls
include physical controls, such as keeping a computer in a locked
room to limit physical access, and logical controls such as
security software programs designed to prevent or detect
unauthorized access to sensitive files.
Access Control and User
Management
Data Access Control
Data access control is a technique
Network
used to regulate employees access
Operating
to files in an organization. It’s System
typically refers to software and Application
Software
activities related to storing, (CBS)
retrieving, or acting on data housed
in a database. Data Access is simply Data
the authorization you have to access
different data files.
Access Control and User
Management
Types of Access Control
Discretionary Access Control (DAC):
Mandatory Access Control (MAC):
Role-Based Access Control (RBAC):
Access Control and User
Management
Discretionary Access Control (DAC):
Discretionary Access Control is a decentralized access control policy that
allows subjects to control access to objects. You can find DAC in
smartphone apps, Google Docs, and Operating Systems worldwide. In
DAC systems, subjects can share information with other users. They can
grant privileges to others.
Access Control and User
Management
Mandatory Access Control (MAC):
Mandatory access control is a centralized access control
system. MAC regulates access to resources based on the
clearance levels of users and the attributes of objects they
seek to access.
Access Control and User
Management
Role-Based Access Control (RBAC):
Role-based access control (RBAC) is a model for authorizing
end-user access to systems, applications and data based on a
user’s predefined role. For example, a security analyst can
configure a firewall but can’t view customer data, while a sales
rep can see customer accounts but can’t touch firewall
settings.
Access Control and User
Management
Key Components of Access Control:
Identification
Authentication
Authorization
Accountability (Auditing)
Access Control and User
Management
Identification:
Identification in access control refers to the process where a
user, system, or entity claims an identity to access
resources. This step typically comes before authentication
and is the first part of the access control process.
Identification is crucial because it establishes the basis for
granting or denying access based on predefined policies or
roles.
Access Control and User
Management
Authentication
What is Authentication?
Authentication is the process of identifying users that request
access to a system, or a part of a system. Access control often
determines user identity according to credentials such as Face
Recognition, Fingerprint, PIN, Password, etc. Other authentication
technologies like authentication apps, QR codes, and Bluetooth are
also used to authenticate user identity
Access Control and User
Management
Authentication
Methods
We can authenticate an identity in three ways:
Something the user knows (such as a password or personal
identification number/ PIN)
Something the user has (a security token or smart card)
Something the user is (a physical characteristic, such as a fingerprint,
called a biometric).
Access Control and User
Management
Authorizatio
n
Authorization in access control refers to the process of
granting or denying access to a resource after the identity of
a user or entity has been verified (through authentication).
Once a user's identity is established, authorization
determines whether they have permission to access specific
resources or perform certain actions based on predefined
access control policies.
Access Control and User
Management
Accountability (Auditing):
Tracking and recording access events to ensure compliance
and detect unauthorized activities.
Access Control and User
Management
Password Policy
A password policy is a set of rules designed to enhance
computer security by encouraging users to employ strong
passwords and use them properly.
A password policy is often part of an organization's official
regulations and may be taught as part of security awareness
training. The password policy may either be advisory or
mandated by technical means.
Access Control and User
Management
Password Management of JBL ICT Security Policy
• The allocation of passwords shall be formally controlled. User
password responsibilities shall be documented in their signed User
Management Form.
• Users shall be initially issued a temporary password which must be
changed at first login. Password should be in good format i.e. should
not contain common passwords like own/spouse/children name, cell
phone number, Birth year, jbl123, pass123, abc123, 1234,123456
etc.
• Users shall always change password in a manner to avoid shoulder
surfing.
• Users shall not share password with anyone and write password on
sticky notes/paper and store in their PC.
• All passwords shall be changed at least every 30 days.
Access Control and User
Management
Password Management of JBL ICT Security Policy
• A User cannot submit a new password that is the same as any of the
last 3 passwords he/she has used.
• Passwords shall be between 8‐12 characters in length; containing a
combination of upper/lower case alphabets, numerals and special
characters i.e. (~!@#$%^&*+).
• Passwords must be changed immediately if it is suspected to be
compromised and reported to CISO/ GM- ICT.
• All Administrative passwords (OS, IOS, Core Banking Solution, DBMS
etc.) shall be locked and must be kept in sealed envelope and stored
in a safe custody.
• The default passwords on all new equipment shall be changed to
conform to the Bank’s password requirements before the equipment
is brought into service.
Access Control and User
Management
Password Management of JBL ICT Security Policy
• Passwords must be rendered unreadable during transmission and
storage on all system components using strong cryptography.
• Password reset requests must be initiated through the Bank’s user
access workflow (confirmation from supervisor or written evidence)
and cannot be initiated by telephone.
• User should never use the "Remember Password" feature in any
application or web sites.
• Login information should not be e-mailed through public channel.
Access Control and User
Management
Password Cracking
Access Control and User
Management
Physical Security
Physical security refers to the protection of people, property,
hardware, software, networks, and data from physical actions or
events that could cause serious loss or damage. This includes
protection from natural disasters, theft, vandalism, terrorism, and
accidental damage.
Access Control and User
Management
Physical Security for Desktop and Laptop
Computers
• Desktop computer shall be connected to UPS.
• Before leaving a desktop or laptop computer unattended, users shall
apply the "Lock Workstation" feature.
• Password protected screen saver shall be used.
• Laptop computers that store confidential or sensitive information must
have encryption technology.
• Desktop and laptop computers and monitors shall be turned off at the
end of each workday.
• Any kind of viruses shall be reported immediately.
• Viruses shall not be deleted without expert assistance unless otherwise
instructed.
• ID and password shall be required to access all desktops and laptops
whenever turned on or restarted.
• All computers shall be placed above the floor level and away from
windows.
Access Control and User
Management
Access Control and User
Management
???
Thank You