Page 46 - CISSO_Prep_ Guide
P. 46

Procedures

            The policy is words, and methods are actions. Procedures
            outline the steps and activities that must be taken to ensure that
            core business activities are performed consistently, in the same
            way, each time, and so that any deviations or errors can be
            noticed quickly. Examples of procedures are a process to set up
            new user accounts, or a change management process. The latest
            user account process ensures that user accounts are only set up
            with proper permissions, set up correctly in a conventional
            manner, and are subject to review and validation. This reduces
            the chance of errors, social engineering, and inconsistent
            account management. By having a defined process that must be
            followed to set up a user account, accounts will be set up the
            same way regardless of which person actually sets up the
   41   42   43   44   45   46   47   48   49   50   51