- Automatically terminating user sessions after a defined period of inactivity.
- There is a documented approval process whereby authorized parties create user accounts and specify required privileges for user access to systems and data. Users require approval for requests to create information system accounts. Each request for information system access is tracked using a ticketing system.
- Using mechanisms (e.g. RBAC, LBAC, ABAC ) to enforce defined access restrictions.



