Assignment 2.docx (2) ISSC 342 Week 2 Assignment ISSC 342 To start this off first one must understand exactly what the concept of least privilege is and what Is meant to do. At its core it is a data security issue, e
...
Assignment 2.docx (2) ISSC 342 Week 2 Assignment ISSC 342 To start this off first one must understand exactly what the concept of least privilege is and what Is meant to do. At its core it is a data security issue, essentially limiting access across an organization or company. For example, you would not want someone working in lets says marketing having access to the same things as someone who is a high-level executive that oversees all departments of the company. The key is to give employees access only to what they need and when they need it so that they can best safely perform their job. The very first thing when setting up a Least privilege system is to get the client or stakeholders involved. To gain company-wide acceptance and properly understand the access levels for the system(s) in question, you will need to fully involve all stakeholders. “If it is an enterprise-wide system, representatives from HR, finance, marketing, etc will need to be involved as they will be best able to articulate who will need access and to what within their specific departments.†(Vogul, 2021) This is more effective and efficient than IT "blindly" dolling out access. The third is the approach on how you decide to implement the least privilege system, one possible way is, allocating access to roles rather than to specific individuals. This can make things far more manageable to maintain. People are less likely to accrue additional access (access creep) over time as roles are easier to revoke. Thi. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . . . . .. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . .. .. . . . . . . . . . . . . . . . . . .. . . . .
[Show More]