Managing risk with policies and security practices
In order to mitigate risk, there are many approaches. Policies are one effective way to meet corporate goals. While they do not guarantee all security goals are met, they are an important layer when we implement defense in depth (DiD). Implementing more layers of security means that if one control fails, we have compensating controls.
Separation of duties (SoD)
When an employee has privileges that enable them to make high-level decisions without needing the consent of another employee, then we are missing essential checks and balances. Consider a chief financial officer (CFO) who approves new suppliers, approves supplier invoices for services, and signs paychecks. This example would allow for fraudulent activities and would be mitigated by establishing accounts receivable and accounts payable business functions.
Job rotation
When employees are in the same job role for a significant amount of time, there is the likelihood...