Systems Security Certified Practitioner – SSCP – Question0210

Which of the following is NOT a form of detective administrative control?

A.
Rotation of duties
B. Required vacations
C. Separation of duties
D. Security reviews and audits

Correct Answer: C

Explanation:

Detective administrative controls warn of administrative control violations. Rotation of duties, required vacations and security reviews and audits are forms of detective administrative controls. Separation of duties is the practice of dividing the steps in a system function among different individuals, so as to keep a single individual from subverting the process, thus a preventive control rather than a detective control. Source: DUPUIS, Cl?ment, Access Control Systems and Methodology CISSP Open Study Guide, version 1.0 (march 2002).