S 2.31 Documentation of authorised users and rights profiles

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Administrator

Documentation of the authorised users, user groups created, and rights profiles on the IT system must be produced. There are various ways to produce this documentation, for example using the following:

A suitable form should be selected and applied uniformly to the entire organisation, if possible.

In particular, the following information relating to the rights granted to users and user groups should be documented:

Authorised users:

Authorised user groups:

The documentation of authorised users and rights profiles should be examined regularly (at least every 6 months) to see if the documentation reflects the rights actually assigned to the users and profiles and if the rights granted still meet the security requirements and are appropriate for the current tasks of the corresponding users. Complete documentation is necessary to be able to monitor the rights granted to the users and user groups.

The documentation must be stored or kept safe so that it is protected against unauthorised access and so that it can still be accessed in case of a large-scale security incident or IT failure. If the documentation is made available in electronic form, then this documentation must be integrated into the data backup procedure.

Review questions: