Comprehensive Guide to IT Security, Incident Response, and Disaster Recovery
1. IT Security Operations Management
1.1 Access Control Principles
- Need to Know : This principle dictates that users should only have access to, knowledge of, or possession of data necessary to perform their specific work tasks. For example, a marketing employee should only have access to customer data relevant to marketing campaigns.
- Principle of Least Privilege : Users should be granted only the level of access and permissions they need for their job. The default access level should be no access. For instance, new users should not be given access to the database unless their job requires it.
- Sepa
超级会员免费看
订阅专栏 解锁全文
1157

被折叠的 条评论
为什么被折叠?



