课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Management review and approval

Management review and approval

- [Instructor] IT and security managers have some key responsibilities when it comes to operational security controls. Managers serve as a critical check and balance in many organizations, and they should routinely review the work of both their own teams and others. Management reviews play two important roles in the security process. First, they provide an important double check on the work performed by employees to verify accuracy and completeness. Second, they reduce fraud and malfeasance by creating a culture of oversight. If employees, particularly privileged users, know that someone is checking their work, they'll be far less likely to engage in unscrupulous activity. Privileged actions are the most important tasks requiring management review. System engineers, application administrators, and other trusted employees often have the ability to override normal security controls and perform actions that would otherwise violate security policies. This is a normal fact of life in any…

内容