User Access Controls Flashcards

1
Q

What’s an Access Control List (ACL)?

A

A table of access rules for computers or systems and the user IDs or assets allowed to access them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What’s and Access Control Entry (ACE)?

A

A single record in an ACL.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What’s a Discretionary Access Control List (DACL)?

A

A means of restricting access to objects based on the identity of subjects and/or groups to which they belong.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What’s a Directory Management System?

A

The collection of software, hardware, and processes that store information about an enterprise, subscribers, or both, and makes that information available to users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are some technology controls for Directory management?

A
  • Access Control Entries (ACEs)
  • Access Control Lists (ACLs)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are some process controls for Directory Management?

A
  • Policies for setting permissions
  • Understanding permission inheritance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What’s the definition of Principle of Least Privilege?

A

Giving a user account only those privileges which are essential to perform its intended functions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are some technology controls for Authorization?

A
  • Identity and Access Management (IAM) applications
  • Directory management
  • Privileged account management tools
  • “Approval before access” controls
  • Logging and retention of approved data certification
  • Identity management (system)
  • Information flow enforcement
  • Software licensing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are some process controls for Authorization?

A
  • Onboarding and role changes
  • Approval processes and workflows
  • Designation of approvers and delegates
  • Audit of entitlements
  • Identity management (manual)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are some technology controls for Authentication and access?

A
  • Identity and access management (IAM) tools
  • Privileged account management (PAM) tools
  • VPN access
  • Password vault
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are some process controls for Authentication and access?

A
  • Access control governance, policies and procedures
  • Authorization/access control matrix management
  • User provisioning and de-provisioning policies and processes
  • Regularly scheduled access audits
  • Change approval boards and processes
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are some technology controls for Privileged account management?

A
  • Identity and access management (IAM) tools
  • Privileged account management (PAM) tools
  • VPN access
  • Password vault
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are some process controls for Privileged account management?

A
  • Policies and procedures
  • Authorization matrix management
  • Change approval boards and processes
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is “user access requirements”?

A

what is needed for secure, successful, and value-adding user access needs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are some technology controls for System user?

A
  • Enforced password criteria compliance
  • Automated warnings, spam filters
  • Anti-virus and anti-malware software
  • Password vault/manager
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are some process controls for System user?

A
  • Policies and procedures related to employee behaviors
  • Anti-reflective monitor screens
  • Locking screens when leaving workstation
  • Not writing down passwords
  • Education campaigns
  • Audits and spot checks