Control Objectives: Identity and Access

No control objectives match the current filters.
Access to the manufacturing system should be restricted to authorized users/devices/3rd parties only and follow the principle of least privilege.
SNow
Classification: ProtectState: Published
Access to the manufacturing system should be restricted to authorized users/devices/3rd parties only and follow the principle of least privilege.
Accounts and authenticators management for the Manufacturing system and applications should be based (where technically possible) on the Active Directory (AD).
SNow
Classification: PreventiveState: Published
Accounts and authenticators management for the Manufacturing system and applications should be based (where technically possible) on the Active Directory (AD).
Centralized Identity Management
SNow
Classification: PreventiveState: Published
A framework of policies, processes, and technologies that facilitates the management of digital identities (e.g. user accounts, service accounts) and the relevant entitlements (access permissions) granted to an identity or a group of identities. Initiate, capture, record, and manage the entire lifec
Password Settings
SNow
Classification: PreventiveState: Published
Password settings must adhere to the Roche Password Management Standard.
Permission Management
SNow
Classification: PreventiveState: Published
Roles must first be defined based on which system, application, or data the entity/user is allowed or not allowed to access. An access-control mechanism must then be used to grant, change or revoke the right to use a particular service or access certain assets.
Privileged Access Management
SNow
Classification: PreventiveState: Published
Protecting credentials with privileged access to IT systems, services, applications and data is critical to the overall security of Roche IT solutions and information assets. This control enables the enforcement, management, and auditing of these credentials through a set of policies, services, and
Secure Login (Multi-Factor Authentication)
SNow
Classification: PreventiveState: Published
Ensures that a computer user is granted access to resources only after successfully presenting two or more pieces of evidence (multiple factors) during authentication. This is in addition to user name and password (first factor). Multi-factor authentication can also be achieved by using Single Sign-
Secure Remote Access for Externals
SNow
State: Retired
The manufacturing system and it's components/peripherals (i.e. PLCs, HMIs, hubs, switches, etc.) should not utilize any default credentials.
SNow
Classification: PreventiveState: Published
The manufacturing system and it's components/peripherals (i.e. PLCs, HMIs, hubs, switches, etc.) should not utilize any default credentials.
The manufacturing system should diffenrenciate between standard user accounts and privileged user accounts (admins etc.).
SNow
Classification: ProtectState: Published
The manufacturing system should diffenrenciate between standard user accounts and privileged user accounts (admins etc.). Privileged user accounts should be limited and the user should be trained in regard to of the elevated permissions and associated risks to their account.
The manufacturing system should provide the capability for an authorized user or role to define and modify the mapping of permissions to roles for all users.
SNow
Classification: ProtectState: Published
The manufacturing system should provide the capability for an authorized user or role to define and modify the mapping of permissions to roles for all users.
The manufacturing system should support user authentication, including unique user id/password combinations, password aging, password strength and failed logon attempt monitoring according to the global password policy.
SNow
Classification: ProtectState: Published
The manufacturing system should support user authentication, including unique user id/password combinations, password aging, password strength and failed logon attempt monitoring according to the global password policy.
The manufacturing system should support user authentication, including unique user id/password combinations, password aging, password strength and failed logon attempt monitoring.
SNow
Classification: PreventiveState: Published
The manufacturing system should support user authentication, including unique user id/password combinations, password aging, password strength and failed logon attempt monitoring.
Graph Explorer