SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationEasy
A security auditor is reviewing an organization's change management process. The auditor notes that changes to critical production systems are sometimes implemented without a formal review by a separate, independent team. Which principle of security operations is MOST directly violated by this practice?
- ALeast Privilege
- BSeparation of Duties
- CDefense in Depth
- DNeed-to-Know
Show answer & explanationAnswer & explanation
Correct answer: B. Separation of Duties
Separation of Duties dictates that no single individual should be able to complete all critical steps of a process without independent review or approval, preventing fraud, error, or malicious activity. Implementing changes without independent review violates this principle.
Why the other options are wrong
- A. Least privilege refers to giving users only the minimum access necessary for their job functions, which is not the primary issue here.
- C. Defense in depth involves multiple layers of security controls, which is a broader concept not specifically addressed by the lack of independent change review.
- D. Need-to-know restricts access to information based on an individual's necessity for their job, which is distinct from the change review process.
Separation of Duties
Separation of Duties is a security principle that divides critical functions among multiple individuals to prevent any single person from having too much control or being able to commit fraud or error without detection.
- Prevents conflicts of interest.
- Reduces risk of error and fraud.
- Requires multiple individuals for critical processes.
- Common in financial and security operations.
Memory trick: Principles are the bedrock of secure operations.