BTIT: Access control and user management

Access control defines how BTIT manages user access to systems, services and information.

Customer expectation

  • Access should be granted only to people who need it for a valid business purpose.
  • Accounts should be created, changed and removed through controlled processes.
  • Administrative access should be limited and protected.
  • Access should be reviewed periodically, especially for sensitive systems.

Support requests

When requesting access changes, include the user name, email address, organisation, requested access, business reason and whether the access is temporary or ongoing.