EBA欧洲银行-Annex-7-Standard-on-Access-Control-and-Authentication_26页_341kb
报告摘要
European Commission Information System Security Policy Summary
Core Content
This document outlines the European Commission's Security Standard on Access Control and Authentication, adopted on 23 June 2011 by Mrs. Irene Souka, Director-General of DG Human Resources and Security. It establishes general principles, organisational guidelines, and procedural requirements for managing user access and authentication across all Commission information systems.
Main Objectives
- Ensure only authorised users access Commission information systems, operating systems, and applications.
- Guarantee individual accountability for user actions.
- Ensure secure processing, transfer, and management of authentication information.
Scope
- Applies to all Commission information systems that store or process data.
- Includes internal users and external users (e.g., Member States, agencies, contractors).
- Covers the entire lifecycle of user rights and privileges, including registration, access, usage, and termination.
- Excludes network-level access control and physical access control.
Key Definitions
| Term | Description |
|---|---|
| User | Any person with authorised access to Commission information systems. |
| Account | A record in the system associated with a user, token, or computer. |
| UserID | A unique identifier for a user account. |
| Registration | Process of applying for an account with a Credential Service Provider. |
| De-registration | Process of removing a user from the system. |
| Authentication | Process of verifying a user's claimed identity. |
| Authorization | Phase where access is verified and granted. |
| Privilege | Supervisor or administrator rights allowing system configuration or access control. |
| Standard Profile | A predefined set of access authorisations grouped by roles. |
| Accountability | Ensures user actions can be uniquely traced. |
General Principles of Access Control
- Confidentiality, Integrity, and Availability (CIA) must be ensured through user access management.
- Need-to-know principle applies: users must have only the minimum access required for their tasks.
- Privileges must be justified and limited to necessary functions.
- Access must be granted only to individuals, with group IDs allowed only for operational reasons.
- Self-registration is permitted but requires documentation and justification in the Security Plan.
- Formal access requests are mandatory for all access authorisations.
- All changes must be logged for auditability.
- Access rights must be revoked immediately when no longer needed.
- Segregation of duties must be implemented between user profiles, system and application administrators.
User Responsibilities
- Users must not share authentication mechanisms.
- Users are accountable for use of their UserID and secrecy of credentials.
- Users must refrain from abuse of rights or privileges.
Access Request and Credentials Management
- Formal registration is required for all users except in specific cases.
- Identity proofing is mandatory during registration.
- Credentials service providers manage access requests, account creation, and credential issuance.
- Group IDs are generally forbidden unless necessary for business operations.
- Access rights must be assigned based on standard role-based profiles.
- Users must be informed of their access rights and any changes.
Privileges Management
- Privileges must be restricted and controlled.
- Special controls apply to privileged profiles and accounts (e.g., root, admin).
- Privileged access requires formal authorisation and documentation.
- Revocation of privileges must occur at the end of the defined period or when no longer needed.
- Training and documentation are required for users to understand and accept their privileges.
- Regular reviews of privileged access are mandatory.
Identification and Authentication
- UserID is used for identification and must be unique.
- Authentication systems are based on one or more factors:
- What the user knows (e.g., passwords, PINs).
- What the user possesses (e.g., tokens).
- What the user is (e.g., biometrics).
- Standard systems must use at least the "what the user knows" factor.
- Public systems may use password-based authentication but it is not mandatory.
- Specific systems require risk-based authentication with defined factors.
Logging and Monitoring
- Access attempts must be logged to ensure auditability.
- Logging includes:
- Invalid login attempts.
- Access to sensitive data or systems.
- Access by privileged users.
- Changes to access rights.
- Use of utilities requiring privileges must be explicitly logged.
- Periodic review of access rights and privileges is required.
- Monitoring reports must be produced and reviewed by the system manager and Security Directorate.
Roles and Responsibilities
System Owner
- Accountable for defining and managing standard profiles.
- Ensures systems are used for their intended purpose.
- May delegate authorisation to IT service providers or system managers.
System Manager
- Manages access requests and credentials.
- Maintains registers of access requests and changes.
- Ensures auditability and monitoring of access control.
- Implements approved access authorisations.
- Reviews privileged access periodically.
User
- Must not share credentials.
- Is accountable for correct use of UserID and secrecy of passwords.
- Must not abuse rights or privileges.
Conclusion
This standard ensures secure, accountable, and controlled access to European Commission information systems. It establishes formal procedures for user registration, access management, and authentication, with clear responsibilities for all parties involved. The policy is aligned with international security norms and supports the broader information system security framework of the Commission.
试读结束,高清完整版pdf/doc/ppt,请点下载