CompTIA Server+ (SK0-005)Security and Disaster RecoveryMedium
A company is implementing a new security policy that requires all user accounts to be reviewed and their access adjusted based on their current job roles quarterly. This practice aligns best with which security principle?
- ALeast privilege
- BAccountability
- CSeparation of duties
- DDefense in depth
Show answer & explanationAnswer & explanation
Correct answer: A. Least privilege
Regularly reviewing and adjusting user access based on current job roles ensures that users only have the minimum necessary permissions to perform their duties. This directly upholds the principle of least privilege, preventing privilege creep.
Why the other options are wrong
- B. Accountability ensures actions can be traced to an individual but doesn't specifically dictate access review frequency or scope.
- C. Separation of duties divides critical tasks among individuals, which is different from adjusting individual user permissions.
- D. Defense in depth involves multiple layers of security controls, not specifically periodic access reviews.
Privilege Creep
The gradual accumulation of access rights by a user over time, often due to job role changes, without corresponding permission removals.
- Violates the principle of least privilege.
- Increases security risk by granting unnecessary access.
- Mitigated by regular access reviews.
Memory trick: Regular checks keep privileges tight.