Page 46 - CISSO_Prep_ Guide
P. 46
Procedures
The policy is words, and methods are actions. Procedures
outline the steps and activities that must be taken to ensure that
core business activities are performed consistently, in the same
way, each time, and so that any deviations or errors can be
noticed quickly. Examples of procedures are a process to set up
new user accounts, or a change management process. The latest
user account process ensures that user accounts are only set up
with proper permissions, set up correctly in a conventional
manner, and are subject to review and validation. This reduces
the chance of errors, social engineering, and inconsistent
account management. By having a defined process that must be
followed to set up a user account, accounts will be set up the
same way regardless of which person actually sets up the