SSCP Systems Security Certified PractitionerAccess ControlsMedium

A company is implementing a new system for managing employee travel requests. The policy states that a travel request must be submitted by the employee, approved by their direct manager, and then approved by the finance department before travel funds are released. No single individual or department can approve a request entirely on their own. This design adheres to which security principle?

  1. ALeast Privilege
  2. BDefense in Depth
  3. CSeparation of Duties
  4. DNeed-to-Know
Show answer & explanation

Correct answer: C. Separation of Duties

Separation of Duties ensures that no single individual has complete control over a critical process or transaction. By requiring multiple approvals from different entities (employee, manager, finance), the company prevents any one person from committing fraud or making errors without oversight.

Why the other options are wrong

  • A. Least Privilege grants minimum necessary access, but the scenario focuses on dividing critical tasks, not just minimum access.
  • B. Defense in Depth uses multiple security layers, which is a broader architectural principle, not specific to the multi-approval process described.
  • D. Need-to-Know provides access only to necessary information, which is related but not the primary principle demonstrated by multi-stage approval.

Separation of Duties

A security principle that divides critical functions and responsibilities among multiple individuals to prevent any single person from having complete control over a process, thereby reducing the risk of fraud or error.

  • Prevents conflicts of interest and insider threats.
  • Requires multiple parties to complete a sensitive task.
  • Often implemented in financial and administrative processes.

Memory trick: Separate Duties: Two heads are better than one for critical tasks.

More Access Controls questions