QS0013-03: Access Control Policy Flashcards

1
Q

QS0013-01: Access Control Policy

What is the purpose of the Access Control Policy?

A

To protect confidentiality, integrity, and availability of information and resources at LabLynx.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

QS0013-01: Access Control Policy

What are “Users” responsible for?

A

User passwords must remain confidential. All actions, processes, or activity performed with a personal user ID is the responsibility of the assigned user.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

QS0013-01: Access Control Policy

What are the DevOps Administrators’ responsibilities?

A
  1. Ensure minimum requirements are met by controlling user IDs and passwords effectively.
  2. Validating approval before granting access.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

QS0013-01: Access Control Policy

Which access control technique provides a straightforward way of granting or denying access for a user performing a specific job?

A

Role-based Access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

QS0013-01: Access Control Policy

Password Management is an example of a:

  1. Corrective Control
  2. Preventive Control
  3. Directive Control
A

Preventive Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

QS0013-01: Access Control Policy

Vendor maintenance accounts must be disabled within 48 hours after use. (True/False)

A

False

Correct Answer: Vendor maintenance accounts must be disabled immediately after use.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

QS0013-01: Access Control Policy

Which form needs to be completed if an individual is terminated?

A

The Personnel Termination Checklist (F0004)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

QS0013-01: Access Control Policy

How soon must the access rights be reviewed if the user changes responsibilities?

A

No later than three business days after responsibility change.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

QS0013-01: Access Control Policy

How quickly must inactive accounts be disabled or removed?

A

Inactive accounts must be disabled after 60 days and may be removed where this will not compromise audit trails.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly