Skip to main content

💼 b. access to, and configuration of, information assets is restricted to the minimum required to achieve business objectives. This is typically referred to as the principle of ‘least privilege’ and aims to reduce the number of attack vectors that can be used to compromise information security;

  • ID: /frameworks/apra-cpg-234/a/1/b

Description

Empty...

Similar

  • Internal
    • ID: dec-c-963930b2

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (3)

PolicyLogic CountFlagsCompliance
🛡️ AWS EC2 Instance IAM role is not attached🟢1🟢 x6no data
🛡️ AWS IAM User has inline or directly attached policies🟢1🟠 x1, 🟢 x5no data
🛡️ Azure Key Vault Role Based Access Control is not enabled🟢1🟢 x6no data

Internal Rules

RulePoliciesFlags
✉️ dec-x-6c93750d1
✉️ dec-x-4157c58a1
✉️ dec-x-c80414561