SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationHard
A security auditor is reviewing an organization's access control policies. The auditor notes that a single administrator has the authority to create user accounts, assign permissions, and approve access requests for critical systems. This situation violates which key security principle?
- ANeed to know
- BLeast privilege
- CSeparation of duties
- DDefense in depth
Show answer & explanationAnswer & explanation
Correct answer: C. Separation of duties
Allowing a single administrator to perform all three critical functions (creating accounts, assigning permissions, and approving access) creates a single point of failure and increases the risk of fraud or error. This directly violates the principle of separation of duties.
Why the other options are wrong
- A. Need to know restricts access to data based on job requirements, not the distribution of administrative functions.
- B. Least privilege ensures users only have necessary permissions, but doesn't address the combination of administrative tasks.
- D. Defense in depth involves multiple layers of security controls, not the assignment of administrative responsibilities.
Separation of Duties
Separation of duties is a security principle that divides critical functions among different individuals to prevent any single person from having too much control or being able to commit fraud or error undetected.
- Prevents single points of failure.
- Reduces the risk of insider threats.
- Requires multiple people to complete a sensitive task.
Memory trick: Don't put all your eggs in one admin's basket.