Study. uk . com
  1. Home
  2. All questions
  3. Question 359

CISSP study material · question 359 of 500

An administrator who configures user permissions is also the person who reviews the audit logs recording permission changes. Which control does SP 800-53 name for this, and what example does it give?

  1. Separation of duties, whose example is that access control administration must not sit with audit administration.
  2. Least privilege, whose example is running processes at the lowest privilege needed.
  3. Information flow enforcement, whose example is blocking unauthorised data movement.
  4. Account management, whose example is periodic recertification of accounts.
Show the answer

Answer: A. Separation of duties, whose example is that access control administration must not sit with audit administration.

AC-5 addresses abuse of authorised privilege, and gives as an example ensuring that security personnel who administer access control functions do not also administer audit functions.

Source: NIST SP 800-53 Rev. 5 (NIST) — SP 800-53 Rev. 5 > AC-5 Separation of Duties

Challenge yourself on this topic → Study as cards