Logical access requirements incorporate the principle of separation of duties
This principle should be included in access requirements to avoid or reduce the potential impact of errors or malicious activities and to prevent potential fraud. For example, the individual requesting access should not also be the person granting access, and the person requesting access should be granted only the minimum set of privileges needed to perform assigned responsibilities. As noted elsewhere in the model, it is important to consider access privileges for devices, systems, and processes that require access to assets and how separation should be applied. For example, systems performing critical safety functions may require additional scrutiny regarding which people or entities may access them, including process control systems they protect.
Related Practices · Input From: Implementing ARCHITECTURE-3a provides input that may be useful for implementing this practice. · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ACCESS-2a, ACCESS-2c, ACCESS-2d, ACCESS-2e, ACCESS-2f.