SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium

A security architect is reviewing the design of a new e-commerce platform. The platform will interact with several third-party payment gateways and shipping providers. To minimize the impact of a potential compromise of any single third-party service, the architect proposes isolating each integration point. Which security principle is the architect applying?

  1. ASeparation of Duties
  2. BCompartmentalization
  3. CDefense in Depth
  4. DLeast Privilege
Show answer & explanation

Correct answer: B. Compartmentalization

Compartmentalization, also known as segmentation or isolation, involves dividing a system into smaller, independent security domains. This limits the scope of compromise, so a breach in one compartment does not automatically affect others.

Why the other options are wrong

  • A. Separation of duties distributes critical tasks among multiple individuals to prevent fraud or error, which is an organizational control.
  • C. Defense in depth involves multiple layers of security controls, which is a broader concept than isolating specific integration points.
  • D. Least privilege refers to giving users/processes only the minimum necessary permissions, not specifically isolating integration points.

Compartmentalization

A security principle that involves dividing a system or network into isolated segments or 'compartments' to limit the impact of a security breach to only the compromised segment, preventing lateral movement to other parts of the system.

  • Also known as segmentation or isolation.
  • Limits the 'blast radius' of an attack.
  • Applied to networks, systems, data, and processes.

Memory trick: Good design builds walls and limits access.

More Systems and Application Security questions