CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityHard

A critical infrastructure organization is implementing a new industrial control system (ICS). Due to the potential for severe physical and environmental damage from a cyberattack, the organization is prioritizing controls to prevent unauthorized access and modification to the ICS. Which of the following security principles is MOST critical to uphold in this context?

  1. ADefense in Depth
  2. BSeparation of Duties
  3. CLeast Privilege
  4. DFail-safe Defaults
Show answer & explanation

Correct answer: C. Least Privilege

While all options are important, 'least privilege' is paramount in highly sensitive environments like ICS. Granting only the minimum necessary access and permissions directly reduces the potential impact of a successful breach or insider threat, which is crucial when physical and environmental damage is a risk.

Why the other options are wrong

  • A. Defense in depth involves multiple layers of security, which is important, but least privilege is a fundamental principle that restricts the impact of a breach at any layer.
  • B. Separation of duties prevents a single individual from controlling an entire critical process, which is important for preventing fraud, but less directly impactful on preventing unauthorized access and modification by an external threat or compromised account.
  • D. Fail-safe defaults ensure that if a system fails, it defaults to a secure state, which is vital for availability and safety but less directly focused on preventing unauthorized access and modification in the first place.

Least Privilege

A security principle that requires that a user or process be given only the minimum set of permissions necessary to perform its job or function.

  • Reduces the attack surface and potential damage.
  • Limits the impact of compromised accounts.
  • Fundamental for strong access control.

Memory trick: For 'Critical' systems, 'Least Privilege' means 'Tiny Key'.

More Information Technology and Security questions