<li> 20100512: Some clarifying tweaks to semantics supplied by Philipp G, added Arb as a role in 9.1.1. but not as critical role. </li>
<li> 20100511: Introduced "Board" term, tightened "approval" semantics, s/wiped/erased/, slight semantic tweaks. </li>
<li> 20100502: Made 7.3 blank, "refer to SM" </li>
<li> 20100424: tidied up 9.4 </li>
<h4 id="s4.1.1">4.1.1. Privileged accounts and passphrases </h4>
Access to Accounts
Access to <span class="change">privileged</span> accounts
(root and user via SSH or console)
must be strictly controlled.
Passphrases and SSH private keys used for entering into the systems
Support Engineers do not have any inherent authority
to take any action,
and they have to get authority on a case-by-case basis.
The authority required in each case must be guided
by this policy or the Security Manual or other clearly
applicable document.
Account Recovery, as documented in the Security Manual.
<span class="change">Member</span> account recovery, as documented in the Security Manual.
Respond to general requests for information or explanation by Members.
Support Engineers cannot make a binding statement.
<li> Team leaders: coordinate with teams, report to Board.</li>
<li> All: respond to Arbitrator's rulings on changes. Respond to critical security issues. Observe.</li>
<li> Board: authorise new individuals and accesses. Coordinate overall. </li>
<li class="change"> Arbitrator: conducts ABCs. Authorises exceptions to policy. </li>
<h4 id="s9.1.2"> 9.1.2. Staffing levels</h4>
<h4 id="s9.1.4.2"> Coverage </h4>
ABC is to be done on every individual in a critical role.
<span class="change">See &sect;1.1.1.</span>
<h4 id="s9.1.4.3"> Documentation </h4>
The Board should deliberate directly and in full.
Board members who are also active in the area should recuse from the vote,
Board members who are also active in the area should
<span class="change">abstain</span>
from the vote,
but should support the deliberations.
Deliberations and decisions should be documented.
All conflicts of interest should be examined.