ExamGecko
Question list
Search
Search

Question 195 - CISM discussion

Report
Export

Implementing the principle of least privilege PRIMARILY requires the identification of:

A.
job duties
Answers
A.
job duties
B.
data owners
Answers
B.
data owners
C.
primary risk factors.
Answers
C.
primary risk factors.
D.
authentication controls
Answers
D.
authentication controls
Suggested answer: A

Explanation:

Implementing the principle of least privilege primarily requires the identification of job duties. Job duties are the specific tasks and responsibilities that an individual performs as part of their role in the organization. By identifying the job duties, the organization can determine the minimum access privileges necessary for each individual to perform their assigned function, and nothing more. This helps to reduce the risk of unauthorized access, misuse, or compromise of information and resources.The principle of least privilege is a key security principle that states that every module (such as a user, a process, or a program) must be able to access only the information and resources that are necessary for its legitimate purpose12.

The other options are not the primary factors that require identification for implementing the principle of least privilege. Data owners are the individuals or entities that have the authority and responsibility to define the classification, usage, and protection of data. Data owners may be involved in granting or revoking access privileges to data, but they are not the ones who identify the job duties of the data users. Primary risk factors are the sources or causes of potential harm or loss to the organization. Primary risk factors may influence the level of access privileges granted to users, but they are not the ones who define the job duties of the users. Authentication controls are the mechanisms that verify the identity of users or systems before granting access to resources. Authentication controls may enforce the principle of least privilege, but they are not the ones who determine the job duties of the users.Reference=

What Is the Principle of Least Privilege and Why is it Important?- F51

4

asked 01/10/2024
Jay Chua
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first