ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingMedium

An organization is conducting a security audit of its critical financial systems. The auditor observes that all system administrators have identical, highly privileged access rights, regardless of their specific job functions, and there is no evidence of regular access reviews. This situation MOST directly violates which fundamental security principle?

  1. AAccountability
  2. BSeparation of Duties
  3. CLeast Privilege
  4. DNeed-to-Know
Show answer & explanation

Correct answer: C. Least Privilege

The principle of Least Privilege dictates that users should only be granted the minimum necessary permissions to perform their job functions. Granting all administrators identical, highly privileged access, irrespective of their specific roles, is a direct violation of this principle.

Why the other options are wrong

  • A. Accountability ensures that actions can be traced to an individual. While lack of access reviews could impact accountability, the primary violation is the excessive privilege itself.
  • B. Separation of duties involves dividing critical tasks among multiple individuals to prevent fraud or error. While related, the core issue here is the *amount* of privilege, not the *division* of tasks.
  • D. Need-to-know is similar to least privilege but focuses on access to specific information, not just general system permissions.

Least Privilege

A security principle that requires giving an individual the minimum level of access or permissions necessary to perform their job function, and no more.

  • Reduces the attack surface and potential damage from compromise.
  • Applies to users, processes, and applications.
  • Often implemented through role-based access control (RBAC).

Memory trick: SECURITY PRINCIPLES are like a fortress: LEAST privilege, SEPARATION of duties, NEED-TO-KNOW, and ACCOUNTABILITY.

More Security Assessment and Testing questions