Best Practices for Access Control Flashcards

1
Q

Implicit Deny

A

All access to a resource is denied by default. Access must be explicitly granted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Explicit Deny

A

Access is granted by default until explicitly denied.

Jenny

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Least Privilege

A

Users are given lowest level access needed to perform their job function.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Separation of Duties

A

Sensitive tasks must use more than one person to conduct them.

An admin user can have an admin account as well as a user account. The individual uses the user account for normal activities and only uses the admin account for tasks that require admin privilege. This is considered a type of separation of duty.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Job Rotation

A

Users are rotated through different jobs to learn more as well as increasing security by helping identify theft, fraud, and abuse of position.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly