CISA Certified Information Systems Auditor – Question2307

Which of the following is a guiding best practice for implementing logical access controls?

A.
Implementing the Biba Integrity Model
B. Access is granted on a least-privilege basis, per the organization's data owners
C. Implementing the Take-Grant access control model
D. Classifying data according to the subject’s requirements

Correct Answer: B

Explanation:

Explanation:
Logical access controls should be reviewed to ensure that access is granted on a least-privilege basis, per the organization’s data owners.