ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsEasy

An organization implemented a security policy where users are only granted the minimum level of access necessary to perform their job functions. This prevents employees from accessing data or systems beyond their specific duties. Which access control principle is being applied?

  1. ALeast privilege
  2. BSeparation of duties
  3. CRole-based access control (RBAC)
  4. DDiscretionary access control (DAC)
Show answer & explanation

Correct answer: A. Least privilege

The principle of least privilege dictates that users should be granted only the minimum necessary permissions to perform their job functions, reducing the risk of accidental or malicious misuse of access.

Why the other options are wrong

  • B. Separation of duties divides critical tasks among multiple individuals to prevent fraud or error.
  • C. RBAC is an access control model that assigns permissions based on roles, which can support least privilege but isn't the principle itself.
  • D. DAC allows resource owners to control access, which doesn't directly enforce minimum necessary access.

Least Privilege

A security principle requiring that a user or process be given only the minimum set of permissions needed to perform its function.

  • Reduces the attack surface.
  • Limits potential damage from compromised accounts.
  • Fundamental to secure system design.

Memory trick: Principles guide security, less is more.

More Access Controls Concepts questions