ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsHard

A security team is conducting an audit of user permissions for a critical financial application. They need to regularly verify that all users still have the appropriate level of access, particularly for those whose roles have changed or who have been inactive. This ensures that access rights align with current business needs and security policies. What is this recurring process called?

  1. AUser provisioning
  2. BRole-based access control (RBAC)
  3. CAccess reviews (or certifications)
  4. DAccount deactivation
Show answer & explanation

Correct answer: C. Access reviews (or certifications)

Access reviews, also known as access certifications, are recurring processes where an organization formally reviews and validates user access rights to ensure they are still appropriate and align with current roles, responsibilities, and security policies. This helps identify and remediate excessive or outdated permissions.

Why the other options are wrong

  • A. User provisioning is the initial granting of access, not the periodic verification.
  • B. RBAC is an access control model, not a process for verifying existing access.
  • D. Account deactivation is part of deprovisioning, which is a specific action, not the overarching review process.

Access Reviews

A recurring process of formally reviewing and validating user access rights to ensure they are appropriate, necessary, and compliant with security policies.

  • Also known as access certifications or recertifications
  • Helps identify orphaned accounts and excessive permissions
  • Crucial for maintaining least privilege and compliance

Memory trick: Access Reviews: 'Review to Renew or Remove.'

More Access Controls Concepts questions