ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A financial institution is implementing a new system for managing customer loan applications. To prevent any single individual from having complete control over a loan approval, the process is designed such that one employee initiates the application, another reviews the credit score, and a third employee provides final approval. This practice is a core principle in access control. What is this principle called?

  1. ALeast Privilege
  2. BTwo-Person Control
  3. CNeed-to-Know
  4. DSeparation of Duties
Show answer & explanation

Correct answer: D. Separation of Duties

Separation of Duties is an access control principle that distributes critical tasks among multiple individuals to prevent any single person from having enough authority to compromise security or commit fraud. The scenario clearly describes dividing the loan approval process among three distinct roles.

Why the other options are wrong

  • A. Least Privilege grants minimum access needed for a role, but doesn't necessarily divide functions.
  • B. Two-Person Control requires two individuals to perform an action, which is a specific implementation of Separation of Duties, but the principle itself is broader.
  • C. Need-to-Know is an application of least privilege, meaning access is granted only when necessary for a task.

Separation of Duties

An access control principle that divides critical or sensitive tasks among multiple individuals to prevent fraud, error, or unauthorized activity.

  • Prevents a single point of failure (human)
  • Requires multiple people for a complete process
  • Reduces opportunity for abuse of power

Memory trick: Separation of Duties: 'Two heads are better than one, especially for security.'

More Access Controls Concepts questions