Educause Security Discussion mailing list archives

Access Control Responsibility Wording


From: "Mclaughlin, Kevin (mclaugkl)" <mclaugkl () UCMAIL UC EDU>
Date: Wed, 12 Sep 2007 14:07:20 -0400

Hi:



I was wondering what other institutions are doing in regards to the wording
on access control requests for sensitive data for 3rd party employees?  Do
you require someone who works for your institution to be responsible for the
3rd party or are can just any Institution employee request access for an
affiliate?



Thanks,

-Kevin





Kevin L. McLaughlin

CISM, CISSP, PMP, ITIL Master Certified

Director, Information Security

University of Cincinnati

513-556-9177 (w)

513-703-3211 (m)

513-558-ISEC (department)





 UC-Logo-800




CONFIDENTIALITY NOTICE: This e-mail message and its content is confidential,
intended solely for the addressee, and may be legally privileged. Access to
this message and its content by any individual or entity other than those
identified in this message is unauthorized. If you are not the intended
recipient, any disclosure, copying or distribution of this e-mail may be
unlawful. Any action taken or omitted due to the content of this message is
prohibited and may be unlawful.





Attachment: smime.p7s
Description:


Current thread: