ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium
A system administrator is configuring access permissions for a new project folder. They want to ensure that if no specific rule grants access to a user, that user is automatically denied access. Which access control principle is being applied here?
- ANeed-to-Know
- BSeparation of Duties
- CImplicit Deny
- DLeast Privilege
Show answer & explanationAnswer & explanation
Correct answer: C. Implicit Deny
Implicit deny is a fundamental security principle that states if a specific permission is not explicitly granted, it is automatically denied. This ensures that access is only provided when positively authorized, reducing the risk of accidental or unintended access.
Why the other options are wrong
- A. Need-to-Know restricts access to information only to those who require it for their job, which is a related but distinct concept.
- B. Separation of Duties prevents a single individual from completing critical tasks alone, addressing collusion, not default access rules.
- D. Least Privilege focuses on granting only the minimum necessary access, not on the default denial of ungranted access.
Implicit Deny
A security principle where access to a resource is denied by default unless explicitly granted by a rule or permission.
- Enhances security by preventing unauthorized access.
- Opposite of implicit allow (permit by default).
- Commonly used in firewalls and access control lists.
Memory trick: If it's not explicitly open, it's implicitly closed.