CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

During a quarterly security review, a security analyst presents a report to the business unit leaders detailing the effectiveness of the organization's Identity and Access Management (IAM) program. The report includes a metric showing the 'Percentage of employees with inactive accounts after 30 days of termination'. This metric is directly supporting which of the following security principles?

  1. ADefense in Depth
  2. BSeparation of Duties
  3. CAccountability
  4. DLeast Privilege
Show answer & explanation

Correct answer: D. Least Privilege

Inactive accounts for terminated employees represent a potential avenue for unauthorized access or abuse, violating the principle of least privilege. By promptly deactivating these accounts, the organization ensures that individuals only retain the minimum necessary access for the shortest possible time, or no access at all post-termination, thus upholding least privilege.

Why the other options are wrong

  • A. Defense in Depth involves multiple layers of security controls, but this specific metric focuses on access rights, not layers.
  • B. Separation of Duties prevents one person from completing a critical task alone, which is not directly addressed by inactive accounts.
  • C. Accountability ensures actions can be traced to an individual, but the metric is about access rights, not tracing actions.

Least Privilege and Account Deactivation

The principle of least privilege dictates that users should only have the minimum necessary access rights to perform their job functions. Prompt deactivation of terminated employee accounts is critical to enforce this principle and prevent unauthorized access.

  • Minimizes potential damage from compromised accounts.
  • Reduces the attack surface.
  • Requires robust offboarding processes.

Memory trick: Access control: Least privilege is key, only what you need.

More Reporting and Communication questions