CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium
An organization is developing a new mobile banking application. During the design phase, the security architect emphasizes the importance of ensuring that the application continues to function even if a single component fails. Which key principle of secure system design is the architect advocating?
- ALeast Privilege
- BFail-Safe Defaults
- CDefense in Depth
- DResilience
Show answer & explanationAnswer & explanation
Correct answer: D. Resilience
Resilience in system design ensures that a system can withstand and recover from failures, maintaining an acceptable level of service. This directly addresses the scenario of continued function despite component failure.
Why the other options are wrong
- A. Least Privilege focuses on granting minimum necessary permissions, not system uptime during failures.
- B. Fail-Safe Defaults means that if a system fails, it should default to a secure state, not necessarily continue operating.
- C. Defense in Depth involves multiple layers of security, not necessarily continuous function upon component failure.
Resilience (System Design)
The ability of a system to withstand and recover from failures, disruptions, or attacks, while maintaining an acceptable level of service and functionality.
- Focuses on continuous operation despite issues.
- Involves redundancy, fault tolerance, and rapid recovery.
- Critical for high-availability systems.
Memory trick: Security is built-in, not bolted-on.