SSCP Systems Security Certified PractitionerAccess ControlsMedium

A security policy states that all administrative actions on critical systems must be approved by a second administrator before execution. This ensures that no single individual can perform a sensitive operation without oversight. Which access control principle is being enforced?

  1. ADefense in depth
  2. BNeed-to-know
  3. CLeast privilege
  4. DSeparation of duties
Show answer & explanation

Correct answer: D. Separation of duties

Separation of duties is an access control principle that divides critical functions among multiple individuals to prevent any single person from being able to perform a complete sensitive operation, thereby reducing the risk of fraud, error, or malicious activity.

Why the other options are wrong

  • A. Defense in depth involves multiple security layers, not the division of responsibilities for a single action.
  • B. Need-to-know focuses on limiting access to information only when necessary for a job function.
  • C. Least privilege focuses on granting minimum necessary access, not on dividing tasks among multiple people.

Separation of Duties

An access control principle that divides critical functions and responsibilities among multiple individuals to prevent any single person from controlling an entire sensitive process end-to-end.

  • Reduces the risk of fraud, error, or malicious acts.
  • Requires multiple parties to complete a critical task.
  • Often implemented with dual control or two-person rules.

Memory trick: Separate duties, share the power, secure the tower.

More Access Controls questions