AC.L1-3.1.2 requires OSCs to “limit information system access to the types of transactions and functions that authorized users are permitted to execute.” Assessment Objective [a] of AC.L1-3.1.2 requires the Assessor to determine whether “the types of transactions and functions that authorized users are permitted to execute are defined.” What assessment method would you use to determine whether the OSC has met this assessment objective?
Submit