ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium
A company is implementing a new payroll system and wants to ensure that no single employee can initiate, approve, and disburse payments. The system is designed so that different individuals are required for each of these distinct steps. Which security principle is being enforced?
- ASeparation of duties
- BNeed-to-know
- CJob rotation
- DLeast privilege
Show answer & explanationAnswer & explanation
Correct answer: A. Separation of duties
Separation of duties is a security principle that divides critical functions among multiple individuals to prevent any single person from having complete control over a process, thereby reducing the risk of fraud or error. The scenario clearly illustrates this by requiring different individuals for initiating, approving, and disbursing payments.
Why the other options are wrong
- B. Need-to-know restricts access to information only when required for a task.
- C. Job rotation involves periodically changing employee roles, which is a control but not the direct principle of dividing tasks.
- D. Least privilege grants minimum necessary access, but doesn't necessarily divide tasks.
Separation of Duties
A security principle that divides critical or sensitive tasks among multiple individuals to prevent any single person from having enough control to commit fraud or errors.
- Reduces the risk of insider threat.
- Requires multiple individuals to complete a transaction.
- Often implemented with access controls (e.g., RBAC).
Memory trick: Separate duties, prevent fraud.