GCC (ACC) - Key Controls Flashcards
ACC01
Individuals access to systems is via a unique username and password which complies with WPP policy.
ACC02
Review current listing of privileged access users by system and certify that they still have a relevant business need for such access.
ACC03
All new privileged user accounts must be subject to appropriate review and approval prior to access being granted.
ACC06
All new general user accounts must be subject to appropriate review and approval prior to access being granted.
ACC07
Review and approve changes to user access
ACC08
Requests to remove or change an individual’s access are raised in a timely manner.
ACC09
Review the complete user lists for all systems to confirm they are active users.
ACC10
Review the shared user ID lists for all systems and certify that all shared user IDs have an appropriate business justification and that mechanisms are in place to prevent mis-use of these accounts.
ACC11
Review the complete user lists for all systems certify that all users have an appropriate business need to support their access.