- Home
- All questions
- Question 359
CISSP study material · question 359 of 500
An administrator who configures user permissions is also the person who reviews the audit logs recording permission changes. Which control does SP 800-53 name for this, and what example does it give?
Show the answer
Answer: A. Separation of duties, whose example is that access control administration must not sit with audit administration.
AC-5 addresses abuse of authorised privilege, and gives as an example ensuring that security personnel who administer access control functions do not also administer audit functions.
Source: NIST SP 800-53 Rev. 5 (NIST) — SP 800-53 Rev. 5 > AC-5 Separation of Duties