Cybersecurity Guidelines for Financial Sector Te…

Cybersecurity Guidelines for FSTI Providers

b) Access Control Mechanisms

Role-Based Access Control (RBAC): - Implement RBAC to assign rights based on the user’s role within the organisation. - Regularly review and update role definitions and access permissions to reflect changes in job functions. Least Privilege Principle: - Grant users the minimum level of access according to roles and responsibilities in carrying out their job duties. - Regularly audit access levels to ensure compliance with the least privilege principle. Access Requests and Approvals - Establish a formal process for requesting, reviewing, and approving access to sensitive systems and data. - Maintain detailed logs of access requests and approvals for audit purposes. Session Management - Implement automatic session timeouts after a period of user’s inactivity to prevent unauthorised access. - Use secure methods to manage session tokens and ensure they are invalidated upon logout .

28

Made with FlippingBook. PDF to flipbook with ease