A financial institution is implementing a new payment processing system. What principle is BEST applied when requiring that payment initiation and payment approval must be performed by different employees?
Segregation of Duties (SoD) is a security principle that divides critical functions among different individuals to prevent fraud, errors, and abuse by ensuring that no single person has complete control over a transaction or process. By requiring multiple people to be involved in sensitive transactions, SoD creates a system where critical tasks are distributed among different individuals, making it more difficult for any single person to commit fraud or make errors without detection. In the given scenario, separating payment initiation from payment approval is a classic example of implementing SoD in a financial context.
The other options are incorrect because:
Defense in depth involves implementing multiple layers of security controls
Least privilege relates to providing minimum necessary access rights
Role-based access is a method of implementing access control based on job functions, which may support SoD but is not the principle itself
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are the main benefits of Segregation of Duties?
Open an interactive chat with Bash
How does Segregation of Duties help in compliance with regulations?
Open an interactive chat with Bash
Can you give an example of how SoD is applied in different industries?
Open an interactive chat with Bash
ISC2 CISSP
Security Architecture and Engineering
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access