CISSP · Question #1485
What is the BEST approach for controlling access to highly sensitive information when employees have the same level of security clearance?
The correct answer is D. Application of least privilege. Applying the principle of least privilege is the best approach for controlling access to highly sensitive information when employees have the same level of security clearance. The principle of least privilege is a security concept that states that every user or process should…
Question
What is the BEST approach for controlling access to highly sensitive information when employees have the same level of security clearance?
Options
- AAudit logs
- BRole-Based Access Control (RBAC)
- CTwo-factor authentication
- DApplication of least privilege
How the community answered
(39 responses)- A8% (3)
- B5% (2)
- C15% (6)
- D72% (28)
Explanation
Applying the principle of least privilege is the best approach for controlling access to highly sensitive information when employees have the same level of security clearance. The principle of least privilege is a security concept that states that every user or process should have the minimum amount of access rights and permissions that are necessary to perform their tasks or functions, and nothing more. The principle of least privilege can provide several benefits, such as: Improving the security and confidentiality of the information by limiting the access and exposure of the sensitive data to the authorized users and purposes Reducing the risk and impact of unauthorized access or disclosure of the information by minimizing the attack surface and the potential damage Increasing the accountability and auditability of the information by tracking and logging the access and usage of the sensitive data Enhancing the performance and efficiency of the system by reducing the complexity and overhead of the access control mechanisms Applying the principle of least privilege is the best approach for controlling access to highly sensitive information when employees have the same level of security clearance, because it can ensure that the employees can only access the information that is relevant and necessary for their tasks or functions, and that they cannot access or manipulate the information that is beyond their scope or authority. For example, if the highly sensitive information is related to a specific project or department, then only the employees who are involved in that project or department should have access to that information, and not the employees who have the same level of security clearance but are not involved in that project or department.
Topics
Community Discussion
No community discussion yet for this question.