| (I) Management procedures and constraints to prevent unauthorized
access to a system. (See: security architecture.)
(O) "The management constraints, operational procedures,
accountability procedures, and supplemental controls established
to provide an acceptable level of protection for sensitive data."
[FP039]
(C) Examples include clear delineation and separation of duties,
and configuration control.
|