Work Product (Artifact): Access Control Discrepancies
A documentation of the Application's discrepancies against the Access Control Standard.
Relationships
RolesResponsible: Modified By:
Input ToMandatory: Optional:
  • None
External:
  • None
Output From
Main Description
A documentation of the Application's discrepancies against the Access Control Standard where the Application does not comply. If there are exceptions, business cases and compensating controls should be documented.
Properties
Optional
Planned
Tailoring
Impact of not havingCould result in an audit finding.
Reasons for not needing
  • The Application fully complies.
  • Upgrades to a system that has no user authentication changes.
  • Projects that do not include applications.