Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A security auditor is reviewing an organization's access control policies. The auditor notes that several employees have retained access to systems and data even after transferring to different departments where their previous access is no longer required for their job functions. Which security principle is being violated?
- ALeast Privilege
- BSeparation of Duties
- CDefense in Depth
- DImplicit Deny
Show answer & explanationAnswer & explanation
Correct answer: A. Least Privilege
The Principle of Least Privilege dictates that users should only be granted the minimum necessary access to perform their job functions. When employees retain access after changing roles, it violates this principle by granting excessive privileges.
Why the other options are wrong
- B. Separation of Duties prevents a single individual from controlling critical functions end-to-end, which is not the issue described.
- C. Defense in Depth involves multiple layers of security controls; while a good practice, it's not the specific principle violated by excessive access.
- D. Implicit Deny is a firewall rule that blocks all traffic not explicitly allowed; it relates to network access, not user role-based access entitlements.
Principle of Least Privilege
A security principle requiring that users, programs, or processes be granted only the minimum necessary access rights to perform their job or function.
- Reduces the attack surface and potential damage from compromise.
- Requires regular review of user permissions.
- Applies to both human users and automated systems.
Memory trick: Access is a Privilege, not a Right.