S 2.65 Checking the efficiency of user separation on an IT system

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Auditor, Administrator, IT Security Officer

Evaluations of the log files or spot checks must be conducted at appropriate intervals to check if the users of the IT systems regularly log off after performing their tasks and if there are any user names used by more than one user.

If it is determined that several users actually do work using the same user name, then they must be informed of their duty to log off after performing their tasks. At the same time, the reasons for this safeguard must be explained to the users since it is in the best interest of the users to follow this safeguard.

If it turns out that the login and logout procedures take too much time and the safeguard is not accepted by the users because of this even though they have been instructed to do so, then alternative safeguards such as the following should be discussed, for example:

Review questions: