Physical and Logical Access Controls
Physical and Logical Access Controls
ACCESS CONTROLS
Submitted by:
Taranpreet Singh Saini
601016
MIT, PUNE
Outline
Internal
Controls
Physical
Access
Controls
Logical
Access
Controls
Regulations
MIT, PUNE
MIT, PUNE
Internal Controls
The process designed, implemented and maintained by those
MIT, PUNE
General
Controls
IS
Controls
Internal
Controls
MIT, PUNE
IS Controls
IS Controls
Application
Controls
IT General
Controls
MIT, PUNE
Objective of IS Controls
Maintaining Confidentiality
Preserving Integrity
Ensuring Availability
MIT, PUNE
Internal Controls
Physical Access
Controls
Logical Access
Controls
MIT, PUNE
Some Terms
Risk
Control
Control Objective
Risk is generally
defined as the
combination of
the probability of
an event and its
negative
consequence
It is generally a
contention and
states a criteria for
implementing and
evaluating the
entitys control
procedures in a
specific area.
Control Design
Control Operation
Documented
Blueprint of the
Control
Actual Execution
of the Control
which is
documented is
operating as
required.
MIT, PUNE
PHYSICAL ACCESS
CONTROLS
General Security
10
MIT, PUNE
11
MIT, PUNE
12
and security.
Restriction of access to sensitive areas.
Proper execution of procedures for Visitor Management
Revocation of access privileges on termination of employment
Constant monitoring of the premises
Screening of baggage and frisking of employees and visitors
MIT, PUNE
LOGICAL ACCESS
CONTROLS
Application and General Security
13
MIT, PUNE
14
MIT, PUNE
15
employees
Revocation of access of terminated employees performed in a
timely manner
Periodical Review of user access roles and rights
Enforcement of access password complexity parameters in all
systems
MIT, PUNE
16
MIT, PUNE
17
MIT, PUNE
18
MIT, PUNE
19
MIT, PUNE
REGULATIONS
Under the Companies Act perspective
20
MIT, PUNE
21
Regulatory Requirement
Section - 134
Section - 143
The auditors report shall state that whether the company has
adequate internal financial control system in place and the
operating effectiveness of such controls.
MIT, PUNE
THANK YOU
22