ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsHard

A Chief Information Security Officer (CISO) is presenting to the board about the organization's security posture. They highlight the importance of regularly reviewing access permissions, disabling accounts for terminated employees promptly, and enforcing strong password policies. These measures collectively support which core security principle?

  1. ALeast Privilege
  2. BData Minimization
  3. CSeparation of Duties
  4. DNeed-to-Know
Show answer & explanation

Correct answer: A. Least Privilege

Regularly reviewing access permissions, disabling terminated employee accounts, and enforcing strong password policies all contribute to ensuring that users (and systems) have only the minimum necessary access rights required to perform their job functions, which is the principle of Least Privilege.

Why the other options are wrong

  • B. Data Minimization focuses on collecting and retaining only essential data, not access controls.
  • C. Separation of Duties divides critical tasks among multiple individuals to prevent a single point of control, which is different from managing individual user access levels.
  • D. Need-to-Know is a principle often implemented using Least Privilege, but Least Privilege is the broader, more encompassing principle for managing all access rights.

Principle of Least Privilege

The Principle of Least Privilege (PoLP) dictates that a user, program, or process should be given only the minimum set of permissions necessary to perform its job function, and no more.

  • Reduces the attack surface.
  • Limits potential damage from compromises.
  • Requires regular review and adjustment of permissions.

Memory trick: Least Privilege: 'Less' access, 'Less' risk.

More Security Operations questions