SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationHard

A security auditor is reviewing an organization's access control policies. The auditor notes that a single administrator has the authority to create user accounts, assign permissions, and approve access requests for critical systems. This situation violates which key security principle?

  1. ANeed to know
  2. BLeast privilege
  3. CSeparation of duties
  4. DDefense in depth
Show answer & explanation

Correct answer: C. Separation of duties

Allowing a single administrator to perform all three critical functions (creating accounts, assigning permissions, and approving access) creates a single point of failure and increases the risk of fraud or error. This directly violates the principle of separation of duties.

Why the other options are wrong

  • A. Need to know restricts access to data based on job requirements, not the distribution of administrative functions.
  • B. Least privilege ensures users only have necessary permissions, but doesn't address the combination of administrative tasks.
  • D. Defense in depth involves multiple layers of security controls, not the assignment of administrative responsibilities.

Separation of Duties

Separation of duties is a security principle that divides critical functions among different individuals to prevent any single person from having too much control or being able to commit fraud or error undetected.

  • Prevents single points of failure.
  • Reduces the risk of insider threats.
  • Requires multiple people to complete a sensitive task.

Memory trick: Don't put all your eggs in one admin's basket.

More Security Operations and Administration questions