Access Control Concepts Quiz
Access Control Concepts Quiz
An organization might opt for high-illumination lighting to deter unauthorized access by making activity in secure areas visible, as it increases the likelihood of malicious actions being noticed by security personnel or captured by surveillance systems. However, this measure could potentially have the vulnerability of a single point of failure if relied upon too heavily without complementary security systems. If the lighting is disabled by malfunction or deliberate sabotage, any area relying solely on illumination for security could become a significant risk point .
A turnstile might be preferred over a fence in situations where controlling and monitoring individual access to a facility is critical. Unlike fences, which serve primarily as barriers, turnstiles can regulate the flow of people, ensuring that only authorized individuals enter the space while preventing 'tailgating' or 'piggybacking' by unauthorized persons. They provide a robust solution for access control by enforcing one-person-at-a-time entry, making them suitable for high-security environments where precise tracking of individuals is necessary .
Bollards and dogs serve as physical security measures by providing deterrence and obstruction, with bollards primarily preventing vehicular access and deliberate ramming attacks, while dogs can detect intrusions and provide active deterrence through presence and noise. However, both share limitations like being unable to independently offer comprehensive perimeter security as they do not prevent or detect unauthorized entry beyond their immediate capability. They rely on human monitoring or additional systems to ensure comprehensive security, and both are limited by environmental conditions such as maintenance or handler availability .
The principle of two-person integrity enhances security by requiring two individuals to be present and agree on actions during operations, thus preventing any single person from undertaking potentially harmful or unauthorized activities unchecked. This principle increases the likelihood of anomalies being detected due to continuous peer oversight, reduces risks of collusion in fraudulent activities, and encourages adherence to protocols due to accountability and mutual accountability among staff members, fostering an environment of trust and checks .
The Change Control Board plays a crucial role in managing security within an organization's IT environment by ensuring that any proposed changes to the system are thoroughly reviewed, tested, and approved before deployment. This process includes identifying potential security enhancements, evaluating their impact, and authorizing changes only after a rigorous evaluation. In the context of Lia's proposal for a configuration change, the Change Control Board ensures that such changes enhance security without disrupting operations or introducing new vulnerabilities .
A password is considered 'confidential' when it is kept secret and known only to the individual it is assigned to. This includes ensuring that the password is not shared, written down in vulnerable locations, or transmitted insecurely. Confidentiality is crucial because it helps preserve the integrity of system access, ensuring that only authorized users can log in and interact with secure systems or data. Maintaining password confidentiality significantly reduces the risk of unauthorized access, data breaches, and compromises .
Requiring two people to be present in the data center during operations, known as two-person integrity, is a security measure designed to prevent unauthorized actions, detect errors promptly, and deter collusion in illegal activities. This policy ensures that no single person can control sensitive operations without oversight, thereby enhancing accountability and reducing risks of malicious activities .
'Piggybacking' or 'tailgating' presents significant risks as it allows unauthorized individuals to enter a controlled area by following closely behind an authorized person, thus bypassing security measures. This risk can be effectively mitigated with physical controls such as turnstiles, which function by allowing only one person to pass at a time and require each person to prove their authorization. Turnstiles enforce the check at every entry, thus preventing multiple persons from entering together undetected, which secures the control of access points .
In access control systems, it is vital for user IDs to be unique to ensure that each user can be distinctly identified and authenticated in the system. This uniqueness prevents identity conflicts, tracks actions accurately for each user, and assists in attributing access and modifications to specific individuals. It supports accountability and audit processes, allowing organizations to trace actions back to the responsible user in case any security incidents or policy violations occur .
'Defense in depth' refers to a multi-layered security strategy designed to protect information by implementing multiple controls across various layers of the IT environment. It focuses on employing diverse protective measures to address different types of threats concurrently. In contrast, 'segregation of duties' specifically aims to separate responsibilities and duties among individuals to minimize the risk of fraud and errors by requiring multiple levels of authorization for critical processes. While defense in depth addresses the breadth of security measures, segregation of duties focuses on in-depth protections against internal threats by dividing potentially conflicting tasks among different people .