Processes: Information Security
No processes match the current filters.
Account Lockout and Reactivation
Information Security
ID: P006
Workflow for managing account lockouts triggered by repeated invalid login attempts and subsequent reactivation as defined in REQ-0300208. Covers automatic lockout thresholds, manual unlock by system administrators after identity verification, and automatic unlock after defined time periods.
Source Documents (1)
Mapped Citations (42)
- 4.10 Enforce Automatic Device Lockout on Portable End-User D...
- 5.3 Disable Dormant Accounts
- 6.2 Establish an Access Revoking Process
- AS.164.308.a3-ii-c
- AS.164.308.a5-ii-c
- Account Monitoring and Control
- Alert on Account Login Behavior Deviation
- DE.CM-03
- Disable Dormant Accounts
- Establish Process for Revoking Access
- HRS-06 Employment Termination
- IAM-07 User Access Changes and Revocation
- IAM-13 Uniquely Identifiable Users
- IAM-14 Strong Authentication
- IAM-16 Authorization Mechanisms
- Identity Verification
- Identity management
- Information access restriction
- Leaver Deactivation
- Limiting System Access
- Lock Workstation Sessions After Inactivity
- Log and Alert on Unsuccessful Administrative Account Login
- Loss Management
- Monitor Attempts to Access Deactivated Accounts
- OS-1.B.1
- PR.AA-01
- PR.AA-02
- PR.AA-03
- PR.AC-P3
- PR.AC-P4
- PR.AC-P6
- PR.IR-01
- PR.PO-P9
- Privileged access rights
- Responsibilities after termination or change of employment
- Return of assets
- Secure authentication
- Security Controls
- Security Monitoring
- System Authorization
- TS.164.312.a2-iii
- TS.164.312.d
End-User and IT Technical Personnel Access Review
Information Security
ID: P038
Annual review of end-user and IT technical personnel access rights to evaluate appropriateness of user roles, training completion, and account activity within computerized systems. Conducted per SOP-0109167, with review frequency defined in the Operational Support Plan or approved document.
Source Documents (2)
Mapped Citations (91)
- 13.5 Manage Access Control for Remote Assets
- 3.3 Configure Data Access Control Lists
- 4.7 Manage Default Accounts on Enterprise Assets and Softwar...
- 5.1 Establish and Maintain an Inventory of Accounts
- 5.3 Disable Dormant Accounts
- 5.4 Restrict Administrator Privileges to Dedicated Administr...
- 5.5 Establish and Maintain an Inventory of Service Accounts
- 6.2 Establish an Access Revoking Process
- 6.8 Define and Maintain Role-Based Access Control
- AS.164.308.a3-i
- AS.164.308.a3-ii-a
- AS.164.308.a3-ii-b
- AS.164.308.a3-ii-c
- AS.164.308.a4-i
- AS.164.308.a4-ii-b
- AS.164.308.a4-ii-c
- Access Management
- Access control
- Access rights
- Account Monitoring and Control
- Audit Log Config Restriction
- Audit Log Protection
- Authority Checks
- Change Management Access
- Control and Monitor Accounts Associated with Penetration Tes...
- Controlled Access Based on the Need to Know
- Controlled Use of Administrative Privileges
- Custom Transaction Evaluation
- DE.CM-03
- Disable Any Unassociated Accounts
- Disable Dormant Accounts
- Electronic Signature (Qualifiied Person)
- Enforce Access Control to Data through Automated Tools
- Ensure All Accounts Have An Expiration Date
- Ensure the Use of Dedicated Administrative Accounts
- Establish Process for Revoking Access
- FireFighter Account Assessment
- FireFighter Governance
- FireFighter Request Access
- FireFighter Time Limits
- Generic Account Governance
- Generic Account Inventory
- Generic Account Review
- HRS-06 Employment Termination
- IAM-01 Identity and Access Management Policy and Procedures
- IAM-03 Identity Inventory
- IAM-04 Separation of Duties
- IAM-05 Least Privilege
- IAM-06 User Access Provisioning
- IAM-07 User Access Changes and Revocation
- IAM-08 User Access Review
- IAM-09 Segregation of Privileged Access Roles
- IAM-10 Management of Privileged Access Roles
- IAM-16 Authorization Mechanisms
- Identity management
- Individual Accountability
- Information access restriction
- Job Change Review
- LOG-04 Audit Logs Access and Accountability
- Late Deactivation Monitoring
- Leaver Deactivation
- Limiting System Access
- Log and Alert on Changes to Administrative Group Membership
- Maintain Inventory of Administrative Accounts
- Maintain an Inventory of Accounts
- Mitigated Risk Review
- Monitor Attempts to Access Deactivated Accounts
- OS-1.B.2
- OS-1.B.5
- PR.AA-01
- PR.AA-05
- PR.AC-P1
- PR.AC-P3
- PR.AC-P4
- PR.DS-P5
- PR.PO-P9
- PS.164.310.a2-iii
- Privileged access rights
- Protect Information through Access Control Lists
- Responsibilities after termination or change of employment
- Role Assessment
- Roles and Responsibilties
- Security Controls
- Security Monitoring
- SoD Dashboard Monitoring
- SoD Risk Review
- System Authorization
- TS.164.312.a1
- TS.164.312.a2-i
- Use Multifactor Authentication For All Administrative Access
- Use Of privileged utility programs
Artifacts (1)
Password Escrow Management
Information Security
ID: P058
Workflow for managing password escrow under specific circumstances as defined in REQ-0300208. Requires a documented rationale, a governing SOP, sealed physical storage, logged access, and regular password rotation per the password management standard.
Source Documents (1)
Mapped Citations (13)
Artifacts (1)
Password Reset and Recovery
Information Security
ID: P059
Workflow for handling initial passwords, forgotten passwords, and password changes as defined in REQ-0300208. Ensures identity verification before any password reset, generation of unique random initial passwords, and secure distribution to the account owner.
Source Documents (1)
Mapped Citations (33)
- 5.2 Use Unique Passwords
- AS.164.308.a5-ii-d
- Authentication information
- Change Default Passwords
- Credential Maintenance
- Dual-Component Requirement: Single Session and New Session P...
- Encrypt Transmittal of Username and Authentication Credentia...
- IAM-02 Strong Password Policy and Procedures
- IAM-13 Uniquely Identifiable Users
- IAM-14 Strong Authentication
- IAM-15 Passwords Management
- Identity Verification
- OS-1.B.1
- Owner Exclusivity
- PR.AA-01
- PR.AA-02
- PR.AA-03
- PR.AA-04
- PR.AC-P1
- PR.AC-P6
- PR.DS-P2
- PR.DS-P5
- Password Monitoring
- Require All Remote Login to Use Multi-factor Authentication
- Require Multi-factor Authentication
- Secure authentication
- Security Baselines (Passwords)
- Signature Uniqueness
- System Authorization
- TS.164.312.d
- Uniqueness of ID/Password
- Use Multifactor Authentication For All Administrative Access
- Use Unique Passwords
Artifacts (1)