Ask the Expert

Criteria for determining access to data warehouse

I have to write a procedure for access to our data warehouse. After all management sign offs, I have to use certain criteria to determine whether the request should be fulfilled. I'm not sure what criteria to use to determine this. I know I can use something like whether it pertains to their job, but there has to be others I can use. Do you have any suggestions?


    Requires Free Membership to View

The request really should just make sense for your company. Is this information something the person needs to complete their job duties? Where will this information be stored? Who will receive this information? If the data needs to follow strict disclosure/confidentiality rules, you may want to consider having all requestees sign a document saying they know and understand these rules. Anyone found not following these rules could be subject to immediate job termination.


For more information on this topic, visit these other SearchSecurity resources:
Ask the Expert: Security content on SearchDatabase
Best Web Links: Database security
Best Web Links: Security policy and infrastructure


This was first published in July 2002

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.