Authorisation is ...

 

... "permitted, accepted and/or agreed by management or some other authority as being in the best interests of the organisation, the workforce, the stakeholders or society at large" [source: SecAware glossary]

... ideally formalised and explicitly documented, providing evidence

... the opportunity to check a proposed course of action

... deciding what should or should not be permitted

... deciding who should or should not be permitted

... one means of issue, incident or error detection

... often informal, implicit and undocumented

... a crossroads, where processes intersect 

... usually manual, sometimes automated

... the acquisition of privileges and rights

... granting or withholding permission

... an important process control point

... only effective if actually checked

... (mis)spelled with a zee 

... a management process

... a governance approach

... the removal of barriers

... the point of no return

... authority to proceed

... a mere formality

... a delaying tactic

... a business issue

... a policy matter

... the green light

... discretionary

... empowering

... sanctioning

... delegation

... go ahead

... approval

... red tape

...

Previous pontifications:

Grab the pencil below to doodle a response.

Popular posts from this blog

Pragmatic ISMS implementation guide (FREE!)

Two dozen information risks that ISO forgot

Philosophical phriday - compliance risk

ISMS internal audit priorities

Reading between the lines of ISO27001 [L O N G]

Passionate dispassion

45 ISO Management Systems Standards

Philosophical phriday - a noncompliance ramble

Adaptive SME security Crowdstrike special