47.5k views
1 vote
The payroll department works with company financial data and had an incident that involved employee's salary being shared across the network. Which of the following would enforce least privilege?

A. Paper shredding
B. Firewalls
C. RFID employee badges
D. Directory permissions

User Peterept
by
8.2k points

1 Answer

2 votes

Final answer:

The measure that enforces the least privilege by limiting access to sensitive financial data to authorized personnel in the presented scenario is 'Directory permissions'. This is because it directly manages who can see and modify files within the network.

Step-by-step explanation:

The concept you are asking about relates to the principle of 'least privilege' within the context of an organization's data security practices. 'Least privilege' means that access to sensitive information and resources is restricted to only the individuals who absolutely need it to perform their job functions. In the scenario where employee salaries were inadvertently shared across the network, the most direct measure to enforce the least privilege would be D. Directory permissions. This is because directory permissions can be set to ensure that only authorized personnel have access to sensitive financial data. Firewalls, while important for network security, do not manage access to files within the network. RFID employee badges are used for physical access control, not for data access restrictions. Paper shredding is a physical security measure which is irrelevant to the protection of digital data.

User Womd
by
7.9k points