CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingHard

A global manufacturing company is implementing a new enterprise resource planning (ERP) system. The project manager identifies a risk that customizations to the ERP system could introduce security vulnerabilities. To address this, the company mandates that all custom code undergo a static application security testing (SAST) review by an independent security team before deployment. Which control design principle is primarily demonstrated by this action?

  1. ASeparation of Duties
  2. BFail-safe Defaults
  3. CDefense in Depth
  4. DPrinciple of Least Privilege
Show answer & explanation

Correct answer: A. Separation of Duties

Mandating an independent security team to conduct SAST on custom code separates the function of code development from the function of security review. This prevents a single individual or team from having control over both introducing and approving potentially vulnerable code, which is the essence of separation of duties.

Why the other options are wrong

  • B. Fail-safe defaults relate to systems defaulting to a secure state in case of failure, which is not directly addressed by the SAST review process.
  • C. Defense in depth involves multiple layers of security. While SAST is a security layer, the principle here is about the independent review process, not just adding a security tool.
  • D. Least privilege relates to granting minimum necessary access, not separating development from security review.

Separation of Duties (Control Design)

A control principle that divides critical functions among multiple individuals or teams to prevent a single person from controlling an entire process and to reduce the risk of fraud or error.

  • Prevents conflict of interest
  • Requires multiple parties for critical tasks
  • Reduces insider threat and error

Memory trick: Secure Design: Think SOL-D (Separation, Open, Least, Defense)

More Risk Response and Reporting questions