SSCP Systems Security Certified PractitionerAccess ControlsEasy
A security administrator is implementing a new access control system that grants users only the permissions necessary to perform their specific job functions and revokes those permissions when their role changes or terminates. Which access control principle is being primarily applied?
- ALeast privilege
- BSeparation of duties
- CDefense in depth
- DNeed-to-know
Show answer & explanationAnswer & explanation
Correct answer: A. Least privilege
The principle of least privilege dictates that users should only be granted the minimum access rights necessary to perform their job functions. Revoking permissions upon role change or termination directly supports this principle.
Why the other options are wrong
- B. Separation of duties involves dividing critical tasks among multiple individuals to prevent fraud or error.
- C. Defense in depth uses multiple security layers to protect assets, not directly related to individual user permissions.
- D. Need-to-know is similar but focuses on information access; least privilege is a broader concept for all resource access.
Least Privilege
A security principle where users and processes are granted only the minimum necessary access rights to perform their job functions or tasks.
- Limits potential damage from errors or malicious acts.
- Reduces the attack surface.
- Requires regular review of user permissions.
Memory trick: Principle Power: Only open doors you need to enter.