BIMF.EN · Question #85
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
The correct answer is B. No. Having access to an application you've never used does not constitute an information security incident - it is a potential access control weakness or policy misconfiguration, but no security event has actually occurred. An information security incident requires that…
Question
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
Options
- AYes
- BNo
How the community answered
(23 responses)- A22% (5)
- B78% (18)
Explanation
Having access to an application you've never used does not constitute an information security incident - it is a potential access control weakness or policy misconfiguration, but no security event has actually occurred. An information security incident requires that confidentiality, integrity, or availability has been compromised, or that a security policy has been actively violated with some adverse effect. Simply possessing access rights, even excessive ones, is a vulnerability to be reviewed and remediated through access management processes, not an incident to be reported.
Why A is wrong: Discovering unused access rights triggers an access review, not an incident response. If the employee had exploited that access to view restricted data, that would be an incident - but awareness alone causes no harm.
Memory tip: Use the "CIA + action" rule - a true security incident must affect Confidentiality, Integrity, or Availability through some action. Unused access is a gap in least-privilege controls, not an incident.
Topics
Community Discussion
No community discussion yet for this question.