Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesEasy

A global manufacturing company is adopting a new enterprise resource planning (ERP) system that integrates various business processes, including finance, human resources, and supply chain management. The cybersecurity architect needs to ensure that the ERP system's access controls align with the principle of least privilege and that user permissions are regularly reviewed and adjusted based on job roles. Which of the following GRC technical strategies is MOST appropriate for achieving these objectives?

  1. AUtilizing a Data Loss Prevention (DLP) system to monitor data exfiltration.
  2. BDeploying an Identity Governance and Administration (IGA) solution.
  3. CImplementing a Security Information and Event Management (SIEM) system for anomaly detection.
  4. DEstablishing a robust Vulnerability Management (VM) program.
Show answer & explanation

Correct answer: B. Deploying an Identity Governance and Administration (IGA) solution.

An IGA solution is specifically designed to manage digital identities and access rights across an organization's systems, ensuring that access aligns with policy and is regularly reviewed. This directly addresses the need for least privilege and regular permission reviews for the ERP system.

Why the other options are wrong

  • A. DLP systems are used to prevent sensitive data from leaving the organization, not for managing internal access controls.
  • C. SIEM focuses on logging and detecting security incidents, not managing access permissions.
  • D. Vulnerability management focuses on identifying and remediating security weaknesses in systems, not on managing user access permissions.

Identity Governance and Administration (IGA)

IGA is a framework that manages digital identities and access rights across an organization, ensuring that access aligns with policy and regulations.

  • Automates user provisioning and deprovisioning.
  • Enforces least privilege and segregation of duties.
  • Facilitates access reviews and certifications.

Memory trick: IGA is the 'Guard' who gives 'Access' to the 'Enterprise'.

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions