ISFS · Question #20
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
The correct answer is B. No. Having access to an application without using it is not an information security incident - it is simply an access control configuration that may warrant a review. An incident requires an actual breach, threat, or harmful event, such as unauthorized access, data leakage, or a…
Question
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
Options
- AYes
- BNo
How the community answered
(47 responses)- A19% (9)
- B81% (38)
Explanation
Having access to an application without using it is not an information security incident - it is simply an access control configuration that may warrant a review. An incident requires an actual breach, threat, or harmful event, such as unauthorized access, data leakage, or a policy violation that causes harm. Merely having access (even if unneeded) is a vulnerability or an administrative oversight, not an incident itself.
Why A is wrong: Calling this an incident would conflate a potential weakness (excess privilege) with an actual security event. The employee hasn't done anything harmful or unauthorized - she simply noticed her access exists.
Memory tip: Think of it this way - a unlocked door is a vulnerability; someone walking through it without permission is an incident. Having access you haven't used = unlocked door. No incident until something bad actually happens.
Topics
Community Discussion
No community discussion yet for this question.