SSCP Systems Security Certified PractitionerAccess ControlsHard

A software development team is building a new application that needs to securely access a database. Instead of embedding database credentials directly into the application code, the developers implement a mechanism where the application requests temporary, short-lived credentials from an identity provider (IdP) just before it needs to connect to the database. These temporary credentials are valid only for a specific duration and a limited set of operations. This approach primarily exemplifies which security principle?

  1. ASeparation of Duties
  2. BNeed-to-Know
  3. CFail-Safe Defaults
  4. DAuditing and Logging
Show answer & explanation

Correct answer: B. Need-to-Know

The 'Need-to-Know' principle dictates that subjects should only have access to the information and resources absolutely necessary to perform their legitimate tasks. By requesting temporary, short-lived, and limited credentials only when needed, the application adheres to this principle, minimizing the exposure of sensitive credentials.

Why the other options are wrong

  • A. Separation of Duties ensures that no single person can complete a critical task alone, which is not directly addressed by how the application retrieves credentials.
  • C. Fail-Safe Defaults ensure that if a security mechanism fails, access is denied rather than granted, which is a broader design principle not specifically exemplified by temporary credentials.
  • D. Auditing and Logging track actions, but the scenario describes a proactive access control mechanism, not a reactive monitoring one.

Need-to-Know Principle

A security principle that states that a subject should only have access to the information and resources that are absolutely necessary to perform their assigned duties.

  • Minimizes the potential damage from compromised accounts.
  • Reduces the attack surface by limiting access.
  • Often implemented with granular permissions and temporary access.

Memory trick: Know your Need: only what's necessary, only when needed.

More Access Controls questions