36 MAC Pt. 1, R. 4.1
Access Management
Cite as 36 Miss. Admin. Code Pt. 1, R. 4.1
Access Management
A. Each agency must limit system access to authorized users, processes acting on behalf
of authorized users, and devices (including other systems). For implementation,
ensure that each asset has strong user authentication as well as network and local
access control lists necessary to implement "need-to-know" and "least privilege".
1. Establish and follow a process, preferably automated, for granting access to
enterprise assets upon new hire, modifying access, or role change of a user.
i. All access to enterprise assets must be authenticated and adhere to
guidance that follows; and
ii. All granting of account access (assignment of privileges) must follow
a strict and defined process (i.e. using account request forms and
approvals thereof by the appropriate personnel). This process is
preferably automated (such as the use of Privileged Access
Management (PAM) systems) but can also be manual.
2. Configure data access control lists based on a user’s need to know. Apply data
access control lists, also known as access permissions, to local and remote file
systems, databases, and applications.
3. Establish and maintain an inventory of all accounts managed in the enterprise.
The inventory must include both user and administrator accounts. The
inventory, at a minimum, should contain the person’s name, username,
start/stop dates, and department. Validate that all active accounts are
authorized, on a recurring schedule at a minimum quarterly, or more
frequently.
i. For implementation, consider having respective department heads or
other appropriate persons review user accounts lists provided by
system administrators for each asset within the Enterprise. Any noted
necessary changes should be provided to the system administrator and
another account listing should be generated for subsequent review and
confirmation the actions were taken.
4. Require users to authenticate to enterprise-managed VPN prior to accessing
enterprise resources on end-user devices.
5. ITS recommends deploying port-level access control. Port-level access control
utilizes 802.1x, or similar network access control protocols, such as
certificates, and may incorporate user and/or device authentication.
i. 802.1x is preferred as it gives the greatest level of security and
flexibility. However, if this is not possible, ITS recommends
configuring "sticky MAC" or simply limiting the MAC address that
can be used for a particular network port, especially in areas where the
connected network devices do not change frequently.
B. Each agency must limit system access to the types of transactions and functions that
authorized users are permitted to execute.
1. Establish and follow a process, preferably automated, for revoking access to
SOM assets, through disabling accounts immediately upon termination, rights
revocation, or role change of a user. Disabling accounts, instead of deleting
accounts, may be necessary to preserve audit trails. If an automated system
cannot be implemented, ITS recommends documenting a manual checklist
that is part of the HR process.
2. Establish and maintain an inventory of service accounts. The inventory, at a
minimum, must contain department owner, review date, and purpose. Perform
service account reviews to validate that all active accounts are authorized, on
a recurring schedule at a minimum quarterly, or more frequently.
i. ITS recommends that this review be conducted in conjunction with the
review described in Part 1, Chapter 4, Section A.3.
3. Centralize access control for all enterprise assets through a directory service
or SSO provider, where supported.
4. Manage access control for assets remotely connecting to enterprise resources.
Determine amount of access to enterprise resources based on: up-to-date anti-
malware software installed, configuration compliance with the enterprise’s
secure configuration process, and ensuring the operating system and
applications are up-to-date.
5. ITS recommends defining and maintaining role-based access control, through
determining and documenting the access rights necessary for each role within
the agency to successfully carry out its assigned duties. Perform access control
reviews of SOM assets to validate that all privileges are authorized, on a
recurring schedule at a minimum annually, or more frequently.
i. Note that if the agency is utilizing the ITS-managed Enterprise VPN
solution, this control will be implemented as part of that service.
C. Each agency must control the flow of sensitive data in accordance with approved
authorizations.
1. Document data flows. Data flow documentation includes service provider data
flows into and out of the organization and should be based on the
organization's data management process. Within that diagram, the
organization should include mechanisms (such as firewalls) that filter the flow
of data, encryption devices that protect the data, and intrusion detection
systems that analyze the data.
i. Review and update documentation annually, or when significant
enterprise changes occur that could impact this safeguard.
2. An authoritative figure should be designated to review and approve changes to
data flow prior to their implementation.
D. Each agency must separate the duties of individuals to reduce the risk of malicious
activity without collusion.
1. ITS recommends defining and maintaining system access authorizations, such
as roles or user groups with differing permissions, to support separation of
duties. Perform authorization reviews, on a recurring schedule at a minimum
annually, or more frequently.
E. Each agency must employ the principle of least privilege, including for specific
security functions and privileged accounts.
1. Establish and maintain a secure network architecture. A secure network
architecture must address segmentation (using implementation methods such
as VLAN access controls and/or firewalls to segment and protect systems),
least privilege (ensuring users only have access to the systems and data
required for their job), and availability (using redundant systems and data
paths), at a minimum.
F. Each agency must use non-privileged accounts or roles when accessing non-security
functions or roles for general computing activities, such as Internet browsing.
1. ITS recommends administrator privileges to dedicated administrator accounts
on SOM assets. Conduct general computing activities, such as internet
browsing, email, and productivity suite use, from the user’s primary, non-
privileged account.
G. Each agency must prevent non-privileged users from executing privileged functions
and audit the execution of such functions.
1. ITS recommends logging sensitive data access, including modification and
disposal.
H. Each agency must limit unsuccessful logon attempts.
1. Enforce automatic account lockout following a predetermined threshold of
local failed authentication attempts.
2. The account should be locked until released by an administrator or until a
specified period of time has passed. The decision for release of an account
after exceeding the threshold of failed authentication attempts should be based
on capabilities of the account.
I. Each agency must ensure that systems have screen locks or password protected screen
savers which are activated after a defined period of inactivity.
1. Configure automatic session locking on SOM assets after a defined period of
inactivity. For general purpose operating systems, the period must not exceed
15 minutes. For mobile end-user devices, the period must not exceed 2
minutes.
J. Each agency must terminate (automatically) a user session after an agency-defined
condition or trigger events requiring session disconnect.
1. Examples of conditions or trigger events requiring automatic session
termination could include defined periods of user inactivity, targeted
responses to certain types of incidents, time-of-day restrictions on information
system use.
K. Each agency shall display a system use notification message or banner to users before
granting access to the system that provides privacy and security notices consistent
with applicable laws, executive orders, directives, regulations, policies, standards, and
guidelines.