SSCP Systems Security Certified PractitionerAccess ControlsMedium
A system administrator is tasked with updating the access control list (ACL) for a shared network folder. The folder currently has entries for 'Finance Group: Read/Write' and 'All Employees: Read'. A new requirement states that specific managers in the 'Finance Group' should also have 'Full Control' over certain subfolders, but not the entire shared folder. Which action should the administrator take FIRST to implement this requirement effectively?
- ARemove the 'All Employees: Read' entry to simplify permissions.
- BAssign 'Full Control' directly to individual manager accounts on the subfolders.
- CCreate a new security group for the specific managers and assign 'Full Control' to the subfolders.
- DModify the 'Finance Group: Read/Write' entry to 'Full Control' for the entire shared folder.
Show answer & explanationAnswer & explanation
Correct answer: C. Create a new security group for the specific managers and assign 'Full Control' to the subfolders.
To manage permissions effectively and follow the principle of least privilege, creating a new security group for the specific managers is the best first step. This allows for centralized management of their elevated permissions only where needed, without modifying broader group permissions or assigning individual rights that become difficult to track.
Why the other options are wrong
- A. Removing 'All Employees: Read' is irrelevant to granting specific managers 'Full Control' and could disrupt general access.
- B. Assigning 'Full Control' to individual accounts is manageable for a very small number, but for 'specific managers' (implying more than one), a group is more scalable and maintainable.
- D. Modifying the 'Finance Group' to 'Full Control' for the entire folder violates least privilege, as not all finance members need that level of access.
Access Control List (ACL) Best Practices
Guidelines for effectively managing permissions on resources to ensure security, maintainability, and adherence to principles like least privilege.
- Use security groups instead of individual users for permissions.
- Apply the principle of least privilege.
- Regularly review and audit ACL entries.
- Avoid excessive or overly broad permissions.
Memory trick: ACL: Groups are great, individuals are chaos.