Article 21
Access control
As part of their control of access management rights, financial entities shall develop, document, and implement a policy that contains all of the following:
(a) |
the assignment of access rights to ICT assets based on need-to-know, need-to-use and least privilege principles, including for remote and emergency access; |
(b) |
the segregation of duties designed to prevent unjustified access to critical data or to prevent the allocation of combinations of access rights that may be used to circumvent controls; |
(c) |
a provision on user accountability, by limiting to the extent possible the use of generic and shared user accounts and ensuring that users are identifiable for the actions performed in the ICT systems at all times; |
(d) |
a provision on restrictions of access to ICT assets, setting out controls and tools to prevent unauthorised access; |
(e) |
account management procedures to grant, change or revoke access rights for user and generic accounts, including generic administrator accounts, including provision on all of the following:
|
(f) |
authentication methods, including all of the following:
|
(g) |
physical access controls measures including:
|
For the purposes of point (e)(i), financial entities shall establish the retention period taking into account the business and information security objectives, the reasons for recording the event in the logs, and the results of the ICT risk assessment.
For the purposes of point (e)(ii), financial entities shall, where possible, use dedicated accounts for the performance of administrative tasks on ICT systems. Where feasible and appropriate, financial entities shall deploy automated solutions for the privilege access management.
For the purposes of point (g)(i), the identification and logging shall be commensurate with the importance of the premises, data centres, sensitive designated areas, and the criticality of the operations or ICT systems located therein.
For the purposes of point (g)(iii), the monitoring shall be commensurate to the classification established in accordance with Article 8(1) of Regulation (EU) 2022/2554 and the criticality of the area accessed.