36 MAC Pt. 1, R. 4.1

Access Management

Year: 2026Length: 1,198 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 4.1

Access Management A. Each agency must limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems). For implementation, ensure that each asset has strong user authentication as well as network and local access control lists necessary to implement "need-to-know" and "least privilege". 1. Establish and follow a process, preferably automated, for granting access to enterprise assets upon new hire, modifying access, or role change of a user. i. All access to enterprise assets must be authenticated and adhere to guidance that follows; and ii. All granting of account access (assignment of privileges) must follow a strict and defined process (i.e. using account request forms and approvals thereof by the appropriate personnel). This process is preferably automated (such as the use of Privileged Access Management (PAM) systems) but can also be manual. 2. Configure data access control lists based on a user’s need to know. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications. 3. Establish and maintain an inventory of all accounts managed in the enterprise. The inventory must include both user and administrator accounts. The inventory, at a minimum, should contain the person’s name, username, start/stop dates, and department. Validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently. i. For implementation, consider having respective department heads or other appropriate persons review user accounts lists provided by system administrators for each asset within the Enterprise. Any noted necessary changes should be provided to the system administrator and another account listing should be generated for subsequent review and confirmation the actions were taken. 4. Require users to authenticate to enterprise-managed VPN prior to accessing enterprise resources on end-user devices. 5. ITS recommends deploying port-level access control. Port-level access control utilizes 802.1x, or similar network access control protocols, such as certificates, and may incorporate user and/or device authentication. i. 802.1x is preferred as it gives the greatest level of security and flexibility. However, if this is not possible, ITS recommends configuring "sticky MAC" or simply limiting the MAC address that can be used for a particular network port, especially in areas where the connected network devices do not change frequently. B. Each agency must limit system access to the types of transactions and functions that authorized users are permitted to execute. 1. Establish and follow a process, preferably automated, for revoking access to SOM assets, through disabling accounts immediately upon termination, rights revocation, or role change of a user. Disabling accounts, instead of deleting accounts, may be necessary to preserve audit trails. If an automated system cannot be implemented, ITS recommends documenting a manual checklist that is part of the HR process. 2. Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose. Perform service account reviews to validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently. i. ITS recommends that this review be conducted in conjunction with the review described in Part 1, Chapter 4, Section A.3. 3. Centralize access control for all enterprise assets through a directory service or SSO provider, where supported. 4. Manage access control for assets remotely connecting to enterprise resources. Determine amount of access to enterprise resources based on: up-to-date anti- malware software installed, configuration compliance with the enterprise’s secure configuration process, and ensuring the operating system and applications are up-to-date. 5. ITS recommends defining and maintaining role-based access control, through determining and documenting the access rights necessary for each role within the agency to successfully carry out its assigned duties. Perform access control reviews of SOM assets to validate that all privileges are authorized, on a recurring schedule at a minimum annually, or more frequently. i. Note that if the agency is utilizing the ITS-managed Enterprise VPN solution, this control will be implemented as part of that service. C. Each agency must control the flow of sensitive data in accordance with approved authorizations. 1. Document data flows. Data flow documentation includes service provider data flows into and out of the organization and should be based on the organization's data management process. Within that diagram, the organization should include mechanisms (such as firewalls) that filter the flow of data, encryption devices that protect the data, and intrusion detection systems that analyze the data. i. Review and update documentation annually, or when significant enterprise changes occur that could impact this safeguard. 2. An authoritative figure should be designated to review and approve changes to data flow prior to their implementation. D. Each agency must separate the duties of individuals to reduce the risk of malicious activity without collusion. 1. ITS recommends defining and maintaining system access authorizations, such as roles or user groups with differing permissions, to support separation of duties. Perform authorization reviews, on a recurring schedule at a minimum annually, or more frequently. E. Each agency must employ the principle of least privilege, including for specific security functions and privileged accounts. 1. Establish and maintain a secure network architecture. A secure network architecture must address segmentation (using implementation methods such as VLAN access controls and/or firewalls to segment and protect systems), least privilege (ensuring users only have access to the systems and data required for their job), and availability (using redundant systems and data paths), at a minimum. F. Each agency must use non-privileged accounts or roles when accessing non-security functions or roles for general computing activities, such as Internet browsing. 1. ITS recommends administrator privileges to dedicated administrator accounts on SOM assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user’s primary, non- privileged account. G. Each agency must prevent non-privileged users from executing privileged functions and audit the execution of such functions. 1. ITS recommends logging sensitive data access, including modification and disposal. H. Each agency must limit unsuccessful logon attempts. 1. Enforce automatic account lockout following a predetermined threshold of local failed authentication attempts. 2. The account should be locked until released by an administrator or until a specified period of time has passed. The decision for release of an account after exceeding the threshold of failed authentication attempts should be based on capabilities of the account. I. Each agency must ensure that systems have screen locks or password protected screen savers which are activated after a defined period of inactivity. 1. Configure automatic session locking on SOM assets after a defined period of inactivity. For general purpose operating systems, the period must not exceed 15 minutes. For mobile end-user devices, the period must not exceed 2 minutes. J. Each agency must terminate (automatically) a user session after an agency-defined condition or trigger events requiring session disconnect. 1. Examples of conditions or trigger events requiring automatic session termination could include defined periods of user inactivity, targeted responses to certain types of incidents, time-of-day restrictions on information system use. K. Each agency shall display a system use notification message or banner to users before granting access to the system that provides privacy and security notices consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
36 MAC Pt. 1, R. 4.1: Access Management | Justis AI