SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationEasy

A security auditor is reviewing an organization's change management process. The auditor notes that changes to critical production systems are sometimes implemented without a formal review by a separate, independent team. Which principle of security operations is MOST directly violated by this practice?

  1. ALeast Privilege
  2. BSeparation of Duties
  3. CDefense in Depth
  4. DNeed-to-Know
Show answer & explanation

Correct answer: B. Separation of Duties

Separation of Duties dictates that no single individual should be able to complete all critical steps of a process without independent review or approval, preventing fraud, error, or malicious activity. Implementing changes without independent review violates this principle.

Why the other options are wrong

  • A. Least privilege refers to giving users only the minimum access necessary for their job functions, which is not the primary issue here.
  • C. Defense in depth involves multiple layers of security controls, which is a broader concept not specifically addressed by the lack of independent change review.
  • D. Need-to-know restricts access to information based on an individual's necessity for their job, which is distinct from the change review process.

Separation of Duties

Separation of Duties is a security principle that divides critical functions among multiple individuals to prevent any single person from having too much control or being able to commit fraud or error without detection.

  • Prevents conflicts of interest.
  • Reduces risk of error and fraud.
  • Requires multiple individuals for critical processes.
  • Common in financial and security operations.

Memory trick: Principles are the bedrock of secure operations.

More Security Operations and Administration questions