PrepAway - Latest Free Exam Questions & Answers

The concept of least privilege currently exists within the context of:

The concept of least privilege currently exists within the context of:

PrepAway - Latest Free Exam Questions & Answers

A.
ISO

B.
TCSEC

C.
OSI

D.
IEFT

Explanation:
Ensuring least privilege requires identifying what the user’s job is, determining the
minimum set of privileges required to perform that job, and restricting the user to a
domain with those privileges and nothing more. By denying to subjects transactions that
are not necessary for the performance of their duties, those denied privileges couldn’t
be used to circumvent the organizational security policy. Although the concept of least
privilege currently exists within the context of the TCSEC, requirements restrict those
privileges of the system administrator. Through the use of RBAC, enforced minimum
privileges for general system users can be easily achieved.


Leave a Reply