课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Segregation of duties

Segregation of duties

- [Instructor] The principle of segregation of duties protects organizations against the malicious actions of a single rogue employee. Organizations implement segregation of duties and two person control to reduce the risk that a single individual can perform a harmful action. The segregation of duties principle says that no single person should possess two permissions, that in combination allow them to perform a sensitive operation. Instead, those permissions should be separated and held by two different groups of people. Account reviews and audits should inspect permissions to ensure that segregation of duties is properly enforced. Let's look at a couple of examples of segregation of duties. One of the most common requirements for segregation of duties comes in the world of accounting. Organizations normally separate the duties of creating new vendors in their accounting systems and authorizing payments to those vendors. This separation prevents a single employee in the accounting…

内容