Protect - Access Management
One of the most significant components of the NIST Framework falls under the “Protect” function, which provides a series of outcomes to secure your systems. This function supports the ability to reduce the attack surface and limit the cyber events' impact on your systems.
Protecting your organization involves six critical cybersecurity categories:
Access Control
Awareness and Training
Data Security
Information Protection Processes and Procedures
Maintenance
Protective Technologies
What is the first thing that comes to mind when you hear “access management?” Most often than not is usernames and passwords. However, here is what you need to know:
1- The credentials must be identified and managed (the entire lifecycle, from creation to deletion)
2- Physical access to your devices also falls under this category
3- Managed remote access
4- Access permissions are managed using the principle of least privilege
5- Network segmentation is also part of access control
6- Make sure all activities are associated with an individual for audit traceability
7- Based on risk, use multi-factor authentication (MFA) as appropriate
Did you know that Access Control was a lot more involved?
========
** FREE GUIDE **
https://www.execcybered.com/asset-man...
Blog: https://www.execcybered.com/blog
Training: https://www.execcybered.com/iso27001f...
Linkedin: / exceccybered
Twitter: / drbillsouza
Instagram: / drbillsouza
Youtube: https://bit.ly/3BGOtPA
Thanks.
Dr. Bill Souza
CEO | Founder
www.execcybered.com