CISSP · Question #161
Refer to the information below to answer the question. An organization experiencing a negative financial impact is forced to reduce budgets and the number of Information Technology (IT) operations sta
The correct answer is B. Loss of data and separation of duties. When IT staff performing integrated security functions are reduced, the primary concern is the potential loss of critical data and the breakdown of separation of duties controls, which are foundational to access security.
Question
Refer to the information below to answer the question. An organization experiencing a negative financial impact is forced to reduce budgets and the number of Information Technology (IT) operations staff performing basic logical access security administration functions. Security processes have been tightly integrated into normal IT operations and are not separate and distinct roles. Which of the following will be the PRIMARY security concern as staff is released from the organization?
Options
- AInadequate IT support
- BLoss of data and separation of duties
- CUndocumented security controls
- DAdditional responsibilities for remaining staff
How the community answered
(18 responses)- A6% (1)
- B83% (15)
- D11% (2)
Why each option
When IT staff performing integrated security functions are reduced, the primary concern is the potential loss of critical data and the breakdown of separation of duties controls, which are foundational to access security.
Inadequate IT support is an operational concern rather than a primary security concern, and does not directly address the logical access security risks created by staff reductions.
Separation of duties is a core security principle that prevents any single individual from having unchecked control over sensitive processes. When staff is released and security roles are consolidated among fewer people, separation of duties is compromised, increasing the risk of fraud, error, and unauthorized access. Additionally, departing staff may take institutional knowledge or access credentials, creating a direct risk of data loss or exposure.
Undocumented security controls may be a secondary risk, but it is not the primary security concern when releasing staff who hold integrated security administration roles.
Additional responsibilities for remaining staff is a workload and operational concern, not a security concern, and does not specifically address the access control vulnerabilities introduced by the staff reduction.
Concept tested: Separation of duties and access security during staff reduction
Source: https://csrc.nist.gov/glossary/term/separation_of_duty
Topics
Community Discussion
No community discussion yet for this question.