§170.315(d)(6) Emergency Access
(d)(6) Emergency access is intended to enable a pre-determined set of users to have ‘admin’ or increased access/permissions during an emergency.
(d)(6) Emergency access is intended to allow a pre-determined set of users to have ‘admin’ or increased access/permissions during an emergency.
Required Extensions
Role-Based Access Control
Features that Support the Certification
Role-Based Access Control Extension
Required Actions
Create an “emergency” role that specific users can temporarily assign to themselves so that they can view otherwise restricted information.
Example
- We created an Emergency message access role, with View Messages as the only permission.
- We have user1 to whom the role Message view not allowed is assigned. Notice that this role does not have any Messages-related permission. It does have permissions to Manage users and to Role-Based Access Control settings.
- When user1 attempts to view messages, the application displays an error.
- In the Role-Based Access Control, user1 assigns to themselves the role Emergency message access in addition to their current role:
- When the setting is saved, user1 is automatically logged out and prompted to log in again. After logging on, user1 is allowed to view messages.