Access Controls Flashcards
1
Q
Test Password Settings
A
- Minimum password length of eight characters.
- Initial log-on uses a one-time password.
- Password composition of alpha and numeric characters.
- Frequently of forced password changes.
- The number of unsuccessful log on attempts allowed before lockout.
- Ability of users to assign their own passwords.
- Number of passwords that must be used prior to using a password again.
- Idle session timeout.
2
Q
Test User Access Authorization
A
- Test new user set-up
- Test terminated users
- Test transferee users
3
Q
Testing of physical security
A
- Obtain a list of employees with access to the data center.
- Confirm that controls are in place to restrict access to only those individuals.
- Also confirm the existence of physical access review.
4
Q
Test privilege user rights
A
- Determine that the ability to perform sensitive IT functions is limited to only appropriate individuals based on their job function.
- include users with the ability to access sensitive utilities when identifying privileged user rights.
- A utility is a program or set of programs that allows a particular task to be executed.
- I ensure that users access is appropriate based on their job description.