CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingHard
A global manufacturing company is implementing a new enterprise resource planning (ERP) system. The project manager identifies a risk that customizations to the ERP system could introduce security vulnerabilities. To address this, the company mandates that all custom code undergo a static application security testing (SAST) review by an independent security team before deployment. Which control design principle is primarily demonstrated by this action?
- ASeparation of Duties
- BFail-safe Defaults
- CDefense in Depth
- DPrinciple of Least Privilege
Show answer & explanationAnswer & explanation
Correct answer: A. Separation of Duties
Mandating an independent security team to conduct SAST on custom code separates the function of code development from the function of security review. This prevents a single individual or team from having control over both introducing and approving potentially vulnerable code, which is the essence of separation of duties.
Why the other options are wrong
- B. Fail-safe defaults relate to systems defaulting to a secure state in case of failure, which is not directly addressed by the SAST review process.
- C. Defense in depth involves multiple layers of security. While SAST is a security layer, the principle here is about the independent review process, not just adding a security tool.
- D. Least privilege relates to granting minimum necessary access, not separating development from security review.
Separation of Duties (Control Design)
A control principle that divides critical functions among multiple individuals or teams to prevent a single person from controlling an entire process and to reduce the risk of fraud or error.
- Prevents conflict of interest
- Requires multiple parties for critical tasks
- Reduces insider threat and error
Memory trick: Secure Design: Think SOL-D (Separation, Open, Least, Defense)