CISSP Domain 7: Least Privilege, SoD & Resource Protection
On the CISSP, security operations questions come down to one move: read whether the scenario wants you to PREVENT an abuse or DETECT one, then match the exact control to that requirement. This Domain 7 deep-dive separates need-to-know from least privilege, walks separation of duties and the detective controls that catch a trusted insider, and covers resource protection and service level agreements. With Fatima, Erica, Lewis, and Beth, we cover the security-operations foundations behind 13% of the current exam, and the question-reading habits that turn ‘BEST’ and ‘MOST’ scenarios into quick, defensible picks.
In this video:
- Need-to-know (the data you may see) versus least privilege (the capability you may use)
- Privilege creep, periodic access reviews, just-in-time access, and prompt deprovisioning
- Separation of duties: why one person creating AND approving a vendor is the classic violation
- Mandatory vacation and job rotation as DETECTIVE controls, and how they differ from prevention
- Dual control and two-person integrity for the few actions you can never trust to one person
- Resource protection: media management, asset and configuration baselines, secure decommissioning, and SLAs
The next video in the series moves into logging and monitoring, where you actually catch the activity these controls are built to surface. Anchored to the (ISC)2 CISSP Detailed Content Outline effective April 15, 2024.
Chapters
- 0:00 The Trusted Employee Who Stole for Years
- 3:43 Need-to-Know vs Least Privilege
- 6:20 Privilege Creep: The Slow Leak
- 9:00 Splitting the Job So No One Owns It
- 11:51 The Vacation That Catches the Thief
- 14:37 Two Keys, One Action
- 17:16 Protecting the Resources Themselves
- 20:00 The Promise You Can Measure
- 22:40 When the Anomaly Engine Watches
- 25:20 Think Like a Manager
- 28:07 Quiz Time
- 31:37 Key Takeaways
On the CISSP, security operations questions come down to one move: read whether the scenario wants you to PREVENT an abuse or DETECT one, then match the exact control to that requirement. This Domain 7 deep-dive separates need-to-know...
Key Topics
- The Trusted Employee Who Stole for Years
- Need-to-Know vs Least Privilege
- Privilege Creep: The Slow Leak
- Splitting the Job So No One Owns It
- The Vacation That Catches the Thief
- Two Keys, One Action
- Protecting the Resources Themselves
- The Promise You Can Measure