Access/Authorization

Authorization is the process of determining what types of activities are permitted. Access is the the right to perform those activities.

Risks:
  • Inability to maintain data integrity.
  • Unauthorized access to computerized records.
  • Access levels exceed those required to perform job requirements.
  • Private customer information might be disclosed to unauthorized individuals.
  • Private customer information might be use for fraudulent purposes.
Controls:
  • Only authorized personnel should have access to confidential data.
  • System access levels should restrict user access in accordance with their job function.
  • Passwords should be used to control access.