CGEIT · Question #127
An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?
The correct answer is A. Authenticating access to information assets based on roles or business rules. To address privacy noncompliance and ensure appropriate ownership of access controls, it is most important to authenticate access based on defined roles or business rules, which establishes clear responsibility for who can access what.
Question
An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?
Options
- AAuthenticating access to information assets based on roles or business rules.
- BImplementing multi-factor authentication controls
- CGranting access to information based on information architecture
- DEngaging an audit of logical access controls and related security policies
How the community answered
(29 responses)- A76% (22)
- B14% (4)
- C3% (1)
- D7% (2)
Why each option
To address privacy noncompliance and ensure appropriate ownership of access controls, it is most important to authenticate access based on defined roles or business rules, which establishes clear responsibility for who can access what.
Implementing access controls based on roles or business rules ensures that individuals are granted access commensurate with their job function and the principle of least privilege, thereby defining the 'owner' of that access entitlement. This systematic approach directly links access privileges to specific organizational functions, which is crucial for demonstrating compliance with privacy regulations by limiting access to personal data to only those who require it for legitimate business purposes.
Implementing multi-factor authentication enhances the strength of authentication but does not inherently address the ownership or appropriateness of what a user can access once authenticated.
Granting access based on information architecture describes how data is structured, but it doesn't establish the ownership or business justification for who should have access.
Engaging an audit is a verification step to assess existing controls and policies, but it's not the primary action to establish appropriate ownership of access controls in the first place.
Concept tested: Role-based access control and ownership
Source: https://learn.microsoft.com/en-us/azure/role-based-access-control/overview
Topics
Community Discussion
No community discussion yet for this question.