ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A small e-commerce company is developing a new online payment gateway. To ensure that the payment process is secure and that only authorized transactions occur, they implement a system where each transaction must be approved by two different managers before it is processed. This control aims to prevent a single point of failure or malicious activity by one individual. Which security principle is primarily being addressed by this two-manager approval process?
- ASeparation of Duties
- BNeed-to-Know
- CLeast Privilege
- DDefense in Depth
Show answer & explanationAnswer & explanation
Correct answer: A. Separation of Duties
Separation of Duties (SoD) is a security principle that divides critical functions among multiple individuals to prevent a single person from having too much control or being able to commit fraud or errors without detection. Requiring two managers to approve a transaction directly implements SoD.
Why the other options are wrong
- B. Need-to-Know restricts access to information based on business necessity, not the division of a task among multiple people.
- C. Least Privilege grants users only the minimum access necessary for their job, which is different from requiring multiple approvals for a single task.
- D. Defense in Depth involves multiple layers of security controls, which is a broader strategy, not specific to this approval process.
Separation of Duties (SoD)
A security principle that distributes critical tasks among multiple individuals to prevent fraud, error, or malicious activity by any single person.
- Prevents a single point of failure in critical processes.
- Reduces the risk of insider threat.
- Often implemented with multi-person approval requirements.
Memory trick: Separate duties so no one person is a single point of failure.