CAS-001 · Question #268
Corporate policy states that the systems administrator should not be present during system audits. The security policy that states this is:
The correct answer is A. separation of duties. Separation of duties is the security principle that divides critical tasks and responsibilities among multiple people so no single individual can perform all steps of a sensitive process - particularly reviewing their own work. Requiring the systems administrator to be absent…
Question
Corporate policy states that the systems administrator should not be present during system audits. The security policy that states this is:
Options
- Aseparation of duties.
- Bmandatory vacation.
- Cnon-disclosure agreement.
- Dleast privilege.
How the community answered
(42 responses)- A93% (39)
- C2% (1)
- D5% (2)
Explanation
Separation of duties is the security principle that divides critical tasks and responsibilities among multiple people so no single individual can perform all steps of a sensitive process - particularly reviewing their own work. Requiring the systems administrator to be absent during an audit of their own systems prevents them from influencing, concealing, or manipulating audit results, ensuring the audit remains objective and independent. Mandatory vacation (B) is a different control designed to detect fraud by having someone else cover duties. NDA (C) is about confidentiality agreements. Least privilege (D) limits what access a user has, not who can be present for an audit.
Topics
Community Discussion
No community discussion yet for this question.