Access Controls: Principles and Solutions | CRISC Exam | ISACA

Principles of Access Controls

Prev Question Next Question

Question

Which of the following are the principles of access controls? Each correct answer represents a complete solution.

Choose three.

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

ABD.

The principles of access controls focus on availability, integrity, and confidentiality, as loss or danger is directly related to these three: -> Loss of confidentiality- Someone sees a password or a company's secret formula, this is referred to as loss of confidentiality.

-> Loss of integrity- An e-mail message is modified in transit, a virus infects a file, or someone makes unauthorized changes to a Web site is referred to as loss of integrity.

-> Loss of availability- An e-mail server is down and no one has e-mail access, or a file server is down so data files aren't available comes under loss of availability.

Access controls are security measures that are used to protect information systems and data from unauthorized access. These controls are designed to ensure that only authorized users are allowed to access sensitive data and that the data is used appropriately.

There are three main principles of access controls that should be followed in order to ensure that the controls are effective:

  1. Confidentiality: This principle refers to the protection of sensitive data from unauthorized access. Confidentiality ensures that only authorized users are allowed to access sensitive information, and that the information is not disclosed to unauthorized parties.

  2. Integrity: This principle refers to the accuracy and completeness of information. Integrity ensures that information is accurate, complete, and free from unauthorized modification. This principle is important because it ensures that the data is reliable and can be trusted.

  3. Availability: This principle refers to the availability of information when needed. Availability ensures that authorized users can access information when they need it. This principle is important because it ensures that the information is accessible and can be used effectively.

In summary, the three principles of access controls are confidentiality, integrity, and availability. These principles work together to ensure that information systems and data are protected from unauthorized access, are reliable and accurate, and are available when needed.