Please enable JavaScript.
Coggle requires JavaScript to display documents.
8.4.5 (Management of Biometrics covers (• Data integrity, authenticity and…
8.4.5
-
BIMS
Management should develop and approve a biometric information management and security (BIMS) policy.
-
the auditor should make sure this policy has been developed and the biometric information is being secured appropriately
With any critical information system, logical and physical controls, including BCPs, should address this area.
Life cycle controls for the development of biometric solutions should be in place to #
to cover the enrollment request,
-
-
identification and authentication procedures for individual enrollment and template creation should be specified in the BIMS policy
biometric device malfunctions or is inoperable, backup authentication methods should also be developed.
Controls should also be in place to protect the sample data as well as the template from modification during transmission.
-
BIOMETRICS
-
best means of authenticating a user’s identity based on a unique, measurable attribute or trait for verifying the identity of a human being.
involves use of a reader device that interprets the
individual’s biometric features before permitting authorized access.
-
-