nerdexam
(ISC)2

CISSP · Question #162

Refer to the information below to answer the question. An organization experiencing a negative financial impact is forced to reduce budgets and the number of Information Technology (IT) operations sta

The correct answer is D. Separating the security function into distinct roles. When security functions are embedded in general IT operations and staff is reduced, separating security into distinct roles ensures proper oversight, accountability, and segregation of duties to maintain acceptable risk levels.

Submitted by priya_blr· Mar 5, 2026Security and Risk Management

Question

Refer to the information below to answer the question. An organization experiencing a negative financial impact is forced to reduce budgets and the number of Information Technology (IT) operations staff performing basic logical access security administration functions. Security processes have been tightly integrated into normal IT operations and are not separate and distinct roles. Which of the following will MOST likely allow the organization to keep risk at an acceptable level?

Options

  • AIncreasing the amount of audits performed by third parties
  • BRemoving privileged accounts from operational staff
  • CAssigning privileged functions to appropriate staff
  • DSeparating the security function into distinct roles

How the community answered

(33 responses)
  • A
    9% (3)
  • B
    3% (1)
  • C
    15% (5)
  • D
    73% (24)

Why each option

When security functions are embedded in general IT operations and staff is reduced, separating security into distinct roles ensures proper oversight, accountability, and segregation of duties to maintain acceptable risk levels.

AIncreasing the amount of audits performed by third parties

Increasing third-party audits is a detective control that identifies problems after the fact but does not proactively restructure internal roles or reduce the ongoing operational risk caused by merged security and IT functions.

BRemoving privileged accounts from operational staff

Removing privileged accounts from operational staff entirely could cripple IT operations, as staff still need appropriate access to perform their duties; it does not address the structural problem of unseparated roles.

CAssigning privileged functions to appropriate staff

Assigning privileged functions to appropriate staff is a partial measure but does not address the core issue of integrating security into distinct, separate roles with proper segregation of duties and accountability.

DSeparating the security function into distinct rolesCorrect

Separating the security function into distinct roles establishes segregation of duties, ensuring that no single reduced-staff member has unchecked control over both operational and security functions. This addresses the root problem - that security is not separate and distinct - by creating dedicated roles with defined responsibilities and oversight, which is a foundational principle of access control and risk management. Even with fewer staff, clearly delineated security roles prevent conflicts of interest and reduce the risk of unauthorized or erroneous actions.

Concept tested: Segregation of duties and separation of security roles

Source: https://www.nist.gov/system/files/documents/2021/06/15/NIST%20SP%20800-53%20Rev%205%20AC-5%20Separation%20of%20Duties.pdf

Topics

#separation of duties#risk mitigation#security roles#organizational security

Community Discussion

No community discussion yet for this question.

Full CISSP Practice