QS0013-03: Access Control Policy Flashcards
QS0013-01: Access Control Policy
What is the purpose of the Access Control Policy?
To protect confidentiality, integrity, and availability of information and resources at LabLynx.
QS0013-01: Access Control Policy
What are “Users” responsible for?
User passwords must remain confidential. All actions, processes, or activity performed with a personal user ID is the responsibility of the assigned user.
QS0013-01: Access Control Policy
What are the DevOps Administrators’ responsibilities?
- Ensure minimum requirements are met by controlling user IDs and passwords effectively.
- Validating approval before granting access.
QS0013-01: Access Control Policy
Which access control technique provides a straightforward way of granting or denying access for a user performing a specific job?
Role-based Access
QS0013-01: Access Control Policy
Password Management is an example of a:
- Corrective Control
- Preventive Control
- Directive Control
Preventive Control
QS0013-01: Access Control Policy
Vendor maintenance accounts must be disabled within 48 hours after use. (True/False)
False
Correct Answer: Vendor maintenance accounts must be disabled immediately after use.
QS0013-01: Access Control Policy
Which form needs to be completed if an individual is terminated?
The Personnel Termination Checklist (F0004)
QS0013-01: Access Control Policy
How soon must the access rights be reviewed if the user changes responsibilities?
No later than three business days after responsibility change.
QS0013-01: Access Control Policy
How quickly must inactive accounts be disabled or removed?
Inactive accounts must be disabled after 60 days and may be removed where this will not compromise audit trails.