From the course: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 22,600 courses taught by industry experts.

Understand account and privilege management

Understand account and privilege management

- [Instructor] One of the fundamental responsibilities of information security professionals is account management. This includes designing strong processes that implement the principles of least privilege and segregation of duties, implementing job rotation schemes, and managing the account lifecycle. The principle of least privilege states that an individual should only have the minimum set of privileges necessary to complete their assigned job duties. The segregation of duties principle says that performing sensitive actions should require the collaboration of two individuals. Account managers issuing permissions should ensure that the permissions they grant users are consistent with these principles. For more information on these two principles, see the authorization video of this course. Many organizations also implement job rotation schemes that are designed to move people around from job to job on a periodic basis. This has obvious personnel benefits by providing teams with a…

Contents