XML Feeds

Search Big4Guy

Custom Search

Sponsored

« 404 Controls Attestation Vs Audit of Financial StatementsSAP xApp Analytics Beginner's Guide »

Role of Security Administrator in Defining Access Controls

Role of Security Administrator in Defining Access Controls

Defining appropriate access controls is very important for organizations in pursuit of Sarbanes Oxley compliance. In an IT environment, access controls need to be in place for securing critical applications, network, databases and operating systems. In complex information technology environments, user authentication is done at the network level. This calls for enhanced user access controls at the network level. Normally, access controls are monitored by the IT operations department. The Security administrator within the IT operations bears the primary responsibility of defining user access controls. The role of the security administrator in defining user access controls includes the following activities:

1. Granting and maintaining user access based on the access control policy defined by the management. System adminstrator ensures that only active users in the organization have a user id, all terminated users are deactivated in the system.

2. Security adminstrator establishes general system controls, including system default passwords, implementing security patches and disabling unneccesary services.

3. The security administrator also monitors and reports to the management on security related issues. He is responsible for escalating serious issues to management so as to enable quick resolution of IT issues.

4. Finally, the security administrator performs peridoic re-certification of user accounts, authenticates user accounts and resolves user access issues using problem tracking mechanims. All of the above activities performed by the security administrator contribute to better access controls which mean better sarbanes oxley compliance.

Related Posts

Developing an Information Security Policy
Concept of Digital Signatures
Recovery Time Objectives
Confidentiality, Integrity & Availability


Permalink 09/07/06 07:27:29 am , by big4guy Email , 160 views, Information Security, Sarbanes Oxley, Leave a comment »

Feedback awaiting moderation

This post has 3 feedbacks awaiting moderation...

Leave a comment


Your email address will not be revealed on this site.

Your URL will be displayed.
(Line breaks become <br />)
(Name, email & website)
(Allow users to contact you through a message form (your email will not be revealed.)