SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium
A security architect is reviewing the design of a new e-commerce platform. The platform will interact with several third-party payment gateways and shipping providers. To minimize the impact of a potential compromise of any single third-party service, the architect proposes isolating each integration point. Which security principle is the architect applying?
- ASeparation of Duties
- BCompartmentalization
- CDefense in Depth
- DLeast Privilege
Show answer & explanationAnswer & explanation
Correct answer: B. Compartmentalization
Compartmentalization, also known as segmentation or isolation, involves dividing a system into smaller, independent security domains. This limits the scope of compromise, so a breach in one compartment does not automatically affect others.
Why the other options are wrong
- A. Separation of duties distributes critical tasks among multiple individuals to prevent fraud or error, which is an organizational control.
- C. Defense in depth involves multiple layers of security controls, which is a broader concept than isolating specific integration points.
- D. Least privilege refers to giving users/processes only the minimum necessary permissions, not specifically isolating integration points.
Compartmentalization
A security principle that involves dividing a system or network into isolated segments or 'compartments' to limit the impact of a security breach to only the compromised segment, preventing lateral movement to other parts of the system.
- Also known as segmentation or isolation.
- Limits the 'blast radius' of an attack.
- Applied to networks, systems, data, and processes.
Memory trick: Good design builds walls and limits access.