【正文】
rinciple 7: Banks should ensure that proper authorisation controls and access privileges are in place for ebanking systems, databases and applications. In order to maintain segregation of duties, banks need to strictly control authorisation and access privileges. Failure to provide adequate authorisation control could allow individuals to alter their authority, circumvent segregation and gain access to ebanking systems ,databases or applications to which they are not privileged. In ebanking systems, the authorisations and access rights can be established in either a centralised or distributed manner within a bank and are generally stored in databases. The protection of those databases from tampering or corruption is therefore essential for effective authorisation control. Appendix III identifies a number of sound practices to help establish proper control over authorisation and access rights to ebanking systems, databases and applications. Principle 10: Banks should take appropriate measures to preserve the confidentiality of key ebanking information. Measures taken to preserve confidentiality should be mensurate with the sensitivity of the information being transmitted and/or stored in databases. Confidentiality is the assurance that key information remains private to the bank and i