From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,200 courses taught by industry experts.

Policies

Policies

- Previously, we discussed the importance of administrative controls. Now, these are those type of controls that we use to create policies that are focused on security risk within our organization. This includes policies and security practices like the separation of duties, job rotation, mandatory vacation, lease privilege, employment and termination procedures, training and awareness for our users, and auditing requirements and their frequencies. Now, in this lesson, we're going to dive a little bit deeper into all of these different concepts. First, we have policies that are focused on the separation of duties. Now, separation of duties is a preventative administrative control, and it's one that should be considered whenever we draft up our organizational authentication and authorization policies. Separation of duties is designed to prevent fraud and abuse by distributing various tasks and approval authorities across numerous different users. For example, let's say you work in the…

Contents