Artifact: Access Control Discrepancies
A documentation of the Application's discrepancies against the Access Control Standard.
Work Product Kinds: Information Security Work ProductsInformation Security Work Products
Relationships
Description
Main DescriptionA documentation of the Application's discrepancies against the Access Control Standard where the Application does not comply. If there are exceptions, business cases and compensating controls should be documented.
Tailoring
Impact of not havingCould result in an audit finding.
Reasons for not needing
  • The Application fully complies.
  • Upgrades to a system that has no user authentication changes.
  • Projects that do not include applications.