nerdexam
Isaca

CDPSE · Question #61

Which of the following is the BEST way to manage different IT staff access permissions for personal data within an organization?

The correct answer is D. Role-based access control. Role-based access control is a method of managing different IT staff access permissions for personal data within an organization by assigning roles to users based on their job functions and responsibilities, and granting access rights to roles based on the principle of least…

Privacy Architecture

Question

Which of the following is the BEST way to manage different IT staff access permissions for personal data within an organization?

Options

  • AMandatory access control
  • BNetwork segmentation
  • CDedicated access system
  • DRole-based access control

How the community answered

(42 responses)
  • B
    5% (2)
  • C
    2% (1)
  • D
    93% (39)

Explanation

Role-based access control is a method of managing different IT staff access permissions for personal data within an organization by assigning roles to users based on their job functions and responsibilities, and granting access rights to roles based on the principle of least privilege and need to know. Role-based access control is the best way to manage different IT staff access permissions for personal data within an organization, as it would help to protect the confidentiality, integrity and availability of the personal data, and also comply with the privacy principles, laws and regulations. Role-based access control would also simplify the administration and maintenance of access permissions, as it would reduce the complexity and redundancy of managing individual user accounts. The other options are not as effective as role-based access control in managing different IT staff access permissions for personal data within an organization. Mandatory access control is a method of managing access permissions for data or resources based on predefined security labels or classifications, such as confidential, secret or top secret, but it does not consider the job functions or responsibilities of the users. Network segmentation is a method of dividing a network into separate segments or zones with different levels of access and control, based on the sensitivity and value of the data or resources, but it does not consider the job functions or responsibilities of the users. Dedicated access system is a method of providing access to data or resources through a separate system or device that is isolated from other systems or networks, but it does not consider the job functions or responsibilities of the users.

Topics

#Access Control#Role-Based Access Control (RBAC)#Personal Data Protection#IT Staff Security

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice