17.3.1 Authorization and Access

All access to, and usage of IT resources must be appropriately requested, approved, registered and audited. A user is defined as any individual or entity granted access to OIST information assets to a level above public classification [link: 17.8.9], or to IT resources above that available to the general public.

Users are responsible for protecting their account information by ensuring that their login, password and other access credentials remain secure at all times. The sharing of account information or passwords is not permitted, and may only be known to, and used by the individual assigned them.
In using these resources, users agree to abide by all relevant University policies, rules, procedures and applicable law. Users must acknowledge this understanding by reading and signing the OIST Graduate University Acceptable Use Policy, via physical signature or digital equivalent [link:  17.6.1].  Account Creation
User accounts will be created via the following process:
・Onboarding into the University via the process relevant to the user’s classification, resulting in registration into the OIST Identity Management System [link:17.8.17]
・Acknowledgement by signature (or digital equivalent) of the OIST Graduate University Acceptable Use Policy [link: 17.6.1]
・Supervisors’ advance authorization to access any IT resources beyond those allocated by default
・Authorization by the relevant Information Asset Manager [link: 17.4.8, 17.4.7] or Information Asset Administrator [link: 17.4.9, 17.8.13] to access any Information Assets managed locally  Account Extension
Requests for extension of access shall be made with valid justification, via the process relevant to the user’s classification. Extension processes will include at least a minimum of supervisors’ approval, and any further approvals as required.  Account Expiry, Deactivation and Deletion
Accounts will be automatically deactivated upon expiry of a user’s term at the University unless extended as described above.
Systems administrators must deactivate invalid accounts when found, or as instructed by the CIO, CISO or legal counsel, and report the event to CIO and CISO.  Access Rights
Should users change roles or responsibilities, supervisors are responsible for ensuring updated access rights are communicated to IT Division, and any relevant Information Asset Managers [link: 17.4.8]. Information Asset Managers are responsible for ensuring that access rights are updated appropriately.  Privileged Users/Systems Administrators
Any user granted escalated privileges [link: 17.8.14] must use them only when required to do so in order to conduct OIST business. System access events of users possessing escalated privileges are to be recorded and monitored at all times.  Shared Accounts
Shared accounts are not in principal permitted, exceptions may be made at the discretion of the system administrators, with concurrence of the CIO or CISO.  Unauthorized Access
All users, including system administrators, must report unauthorized access to the CISO immediately if suspected.

Table of Contents