Article 10
|
(Management of Network Equipment Rules)
- Amendments to network equipment rules (network access rules, firewall rules, etc.) shall be made upon a review of user needs and evaluation of the level of risk to information and communication security, and be documented for reference, in the event of any addition, change, or deletion thereto.
- Network equipment rules shall be established granting users the least privilege and using positive lists in principle.
- An organization shall review network equipment rules at least once a year, evaluating their adequacy and removing unnecessary provisions.
|