CCSP · Question #321
Access should be based on ____________. Response:
The correct answer is B. Business needs and acceptable risk. Access to resources should fundamentally align with an organization's business needs while also considering the acceptable level of associated risk.
Question
Access should be based on ____________. Response:
Options
- ARegulatory mandates
- BBusiness needs and acceptable risk
- CUser requirements and management requests
- DOptimum performance and security provision
How the community answered
(22 responses)- A5% (1)
- B91% (20)
- D5% (1)
Why each option
Access to resources should fundamentally align with an organization's business needs while also considering the acceptable level of associated risk.
While regulatory mandates inform security policies, they are not the sole basis for all access decisions, which should primarily derive from internal business operations.
Access control policies should always be driven by genuine business requirements, ensuring users have only the necessary permissions to perform their job functions effectively. Simultaneously, an organization must evaluate the potential security risks associated with granting such access and establish an acceptable risk threshold to protect assets.
User requirements and management requests are important inputs but must be vetted against actual business needs and the associated risks, not taken as the ultimate basis without further analysis.
Optimum performance and security provision are desired outcomes but do not define the underlying criteria for granting access rights.
Concept tested: Principles of access control
Source: https://learn.microsoft.com/en-us/azure/architecture/framework/security/design-access-control
Topics
Community Discussion
No community discussion yet for this question.