Skip to main content

User Access Priviliges and Control Policies

Information can exist in many forms. It can be written on paper, hosted, stored and transmitted digitally or spoken in conversation. Whatever form the information takes, when appropriate, steps can be taken to help prevent disclosure to unauthorized individuals or entities. Your data security program will balance your business and operational needs while maintaining data confidentiality (only authorized users can access the information) and data integrity (preventing the data from being corrupted or changed).

Each department can establish a data access privilege and control policy for employees and third parties. The policy can specify who needs access to confidential data, how this data should be secured, and procedures for effectively deleting or destroying data once it is no longer needed by the department and/or company. Some considerations related to user access privileges and control policies include:

The business manager

To help protect the confidentiality and integrity of company information, provide access on a need-to-know and need-to-use basis only. Have business managers develop information access privileges and control policies. Business managers may be in the best position for managing the protection of the information, assigning the classification level of the information, determining who is permitted to access the information and periodically reassessing the classification and access levels.

The business manager and the Chief Information Security Officer (CISO) should maintain a log of user access privileges to confirm that employees have the appropriate access privileges.  The log should be regularly updated after any changes, e.g., if user’s job functions have changed or accounts have not been accessed for a specified extended period, access should be removed. In addition, the business manager and CISO should maintain a log of contractors or other third parties who have access to specific data, under what circumstances, and how those access privileges will be managed and tracked.

User access privileges and control policies

Establish information access privileges and control policies for all employees and third parties. Align access with the job requirements, the information classification level and with who needs access to the information to perform their assigned duties. Some information may be accessible to everyone; some information may be restricted to a specific department; and some information may be authorized and accessed solely by a set of key personnel.

Requiring users to enter a unique user ID (e.g., employee number) in addition to a password can help to enforce access privileges and monitor usage.

Third parties who have access to specific data, under what circumstances and how those access privileges will be managed and tracked.

Encryption

Encryption can be employed to protect any data that your company considers sensitive or is required to comply with any regulatory or contractual security requirements. Encryption can provide an excellent safeguard to help prevent information stored on files, directories, or disks from falling into unauthorized hands. Encryption software for data in storage and in transit will vary in type and strength. The security level required can be increased with the sensitivity of the information.

Most businesses need data to be moved, accessed and used by employees and even shared with key suppliers or contractors. Security experts are fond of saying that data is most at risk when it’s on the move. Whenever sensitive data is transmitted externally, consider encrypting it. Additionally, if sensitive data is being transmitted internally over less secure networks, consider encrypting it.

Management of removable computer media

Control policies can be established for all employees to control the downloading of sensitive information onto portable data storage devices such as PDAs, CDs and thumb drives. The best protection is to store sensitive data only in secure places. Some controls to consider include:

  • Define what information or networked equipment can be taken home or on business trips.
  • Restrict company data from being stored or transmitted on personal email accounts or other non-company networks.
  • Require passcodes on any devices that have access to sensitive information.
  • Encrypt all downloaded sensitive information.
  • Securely dispose of or erase any reusable media when no longer required. Be sure to comply with your company records retention and disposal policy.
  • Require all employees to comply with your company mobile device security policy.
  • Monitor and control sensitive information downloads onto portable devices. You may be able to configure your network to record and log the download(s) and the user ID. See Travelers Risk Control bulletin Network Logging and Monitoring.

Scheduled reviews of user privileges

On a scheduled basis, have business managers confirm that user access privileges are current, properly assigned and unauthorized users have been removed. 

Related resources

Human Resource Controls in Data Security

This article discusses the importance of human resource controls as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related resources

Data Inventory and Classification

Learn about the importance of inventory and classifying your data as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related resources

Cyber Security Training for Employees

A large number of information security incidents are directly attributable to inadequate data technology user training. This bulletin discusses providing employees and contractors with appropriate training to recognize cyber threats.