CISSP · Question #162
Refer to the information below to answer the question. An organization experiencing a negative financial impact is forced to reduce budgets and the number of Information Technology (IT) operations sta
The correct answer is D. Separating the security function into distinct roles. When security functions are embedded in general IT operations and staff is reduced, separating security into distinct roles ensures proper oversight, accountability, and segregation of duties to maintain acceptable risk levels.
Question
Options
- AIncreasing the amount of audits performed by third parties
- BRemoving privileged accounts from operational staff
- CAssigning privileged functions to appropriate staff
- DSeparating the security function into distinct roles
How the community answered
(33 responses)- A9% (3)
- B3% (1)
- C15% (5)
- D73% (24)
Why each option
When security functions are embedded in general IT operations and staff is reduced, separating security into distinct roles ensures proper oversight, accountability, and segregation of duties to maintain acceptable risk levels.
Increasing third-party audits is a detective control that identifies problems after the fact but does not proactively restructure internal roles or reduce the ongoing operational risk caused by merged security and IT functions.
Removing privileged accounts from operational staff entirely could cripple IT operations, as staff still need appropriate access to perform their duties; it does not address the structural problem of unseparated roles.
Assigning privileged functions to appropriate staff is a partial measure but does not address the core issue of integrating security into distinct, separate roles with proper segregation of duties and accountability.
Separating the security function into distinct roles establishes segregation of duties, ensuring that no single reduced-staff member has unchecked control over both operational and security functions. This addresses the root problem - that security is not separate and distinct - by creating dedicated roles with defined responsibilities and oversight, which is a foundational principle of access control and risk management. Even with fewer staff, clearly delineated security roles prevent conflicts of interest and reduce the risk of unauthorized or erroneous actions.
Concept tested: Segregation of duties and separation of security roles
Source: https://www.nist.gov/system/files/documents/2021/06/15/NIST%20SP%20800-53%20Rev%205%20AC-5%20Separation%20of%20Duties.pdf
Topics
Community Discussion
No community discussion yet for this question.