§170.315(d)(1) Authentication, Access Control, Authorization
Cures criteria for §170.315(d)(1) Authentication, Access Control, Authorization.
(d)(1) Authentication, Access Control, and Authorization includes limiting access by user name and password, ensuring unique user IDs, and enabling role-based access control.
Required Extensions
Features that Support the Certification
- Use of the Role-Based Access Control Extension
- Validation of username and passwords
- Prevention of duplicate usernames
- Creation of user roles that limit/enable viewing and managing different areas of the application
- Disable user accounts as needed
Required Actions
- Administrator needs to maintain/update valid/invalid users
- Administrator needs to create roles and assign them to each user based on company’s policies