CISSP · Question #740
When designing a networked Information System (IS) where there will be several different types of individual access, what is the FIRST step that should be taken to ensure all access control requiremen
The correct answer is B. Create a user access matrix.. The first step to take when designing a networked Information System (IS) where there will be several different types of individual access is to create a user access matrix. A user access matrix is a table that defines the access rights and permissions of each user or user group
Question
When designing a networked Information System (IS) where there will be several different types of individual access, what is the FIRST step that should be taken to ensure all access control requirements are addressed?
Options
- ACreate a user profile.
- BCreate a user access matrix.
- CDevelop an Access Control List (ACL).
- DDevelop a Role Based Access Control (RBAC) list.
How the community answered
(28 responses)- A7% (2)
- B75% (21)
- C4% (1)
- D14% (4)
Explanation
The first step to take when designing a networked Information System (IS) where there will be several different types of individual access is to create a user access matrix. A user access matrix is a table that defines the access rights and permissions of each user or user group to each resource or function in the system. A user access matrix helps to ensure that all access control requirements are addressed, such as the principle of least privilege, the principle of separation of duties, and the principle of need to know. A user access matrix also helps to simplify and standardize the implementation and administration of access control policies and mechanisms.
Topics
Community Discussion
No community discussion yet for this question.