Who should be authorised to access data?

Text only site | Graphic site


Site Navigation:

Understanding  |  Planning  |  Building  |  Protecting  |  Managing  |  Improving


In this section:

About protecting  |  Why be secure?  |  Where do I start?  |  What can I do?  |  Key issues  |  Top ten e-security tips


In this sub-section:

The security program lifecycle  |  Who will administer and manage the process?  |  Who should be authorised to access data?  |  How do I know who is accessing my information?  |  How do I keep track of everything?


   


Who should be authorised to access data?

Employees at various levels throughout an organisation will require access to different types of information and data. This sometimes applies to contractors working within your business.

Authorisation refers to the granting of access rights to data, software and communications, based on the allocation of tasks to the users to allow them to perform their job.

For example, all employees may need to access word processing software, but are only granted rights to directories containing files that are directly relevant to them. The same applies to spreadsheet software. All users may need access to the software but only certain people can have access to the company's financial records created using that software. In this case, access to the software is unrestricted, but access to files containing data is provided on a restricted basis.

What to do

As additional functions, features and capabilities are added to your company website, overall security should be adequately controlled. User access policies and procedures should be developed and implemented to ensure that an appropriate level of access is allowed.

For example, you may wish certain suppliers to have access to your system to share data such as inventory records or automatic ordering and re-stocking processes. You should ensure that the appropriate security controls are in place to prevent unauthorised use of this access point that would allow people to access other parts of your network where there is confidential and sensitive information.

Next topic in this section >


Resources:
using this site | who can help | e-business training | e-business references | case studies | quick tools | glossary

Graphic site
Last date modified: 16 May 2009
Page URL: http://www.e-businessguide.gov.au/protecting/what/auth