A security architect at a large financial services company is designing a new system for high-value transactions. To mitigate the risk of internal fraud, the design mandates that no single employee can initiate, approve, and finalize a transfer. Instead, these actions must be assigned to different individuals based on their defined job functions. Which security principle is most directly and fundamentally addressed by this design requirement?
Segregation of Duties (SoD) is a security principle that divides critical functions among different individuals to prevent fraud, errors, and abuse by ensuring that no single person has complete control over a transaction or process. By requiring multiple people to be involved in sensitive transactions like initiating, approving, and finalizing a transfer, SoD creates a system of checks and balances, making it significantly more difficult for any single person to commit fraud without collusion.
The other options are incorrect because:
Defense in depth involves implementing multiple layers of security controls, and while SoD can be one of those layers, it is not the overarching principle of layering itself.
Least privilege relates to providing the minimum necessary access rights for a user to perform their job functions. While related, it doesn't specifically address the requirement of splitting a single process among multiple people.
Role-based access control (RBAC) is a method of implementing access control based on job functions. It is a common and effective way to enforce SoD, but SoD is the fundamental principle being applied, not the implementation mechanism.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does Segregation of Duties reduce fraud risks?
Open an interactive chat with Bash
How is Segregation of Duties implemented in an organization?
Open an interactive chat with Bash
Is Role-Based Access Control related to Segregation of Duties?
Open an interactive chat with Bash
ISC2 CISSP
Security Architecture and Engineering
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .