From the course: CISSP Cert Prep (2021): 6 Security Assessment and Testing
Unlock the full course today
Join today to access over 22,400 courses taught by industry experts or purchase this course individually.
Management review and approval
From the course: CISSP Cert Prep (2021): 6 Security Assessment and Testing
Management review and approval
- [Instructor] IT and security managers have some key responsibilities when it comes to operational security controls. Managers serve as a critical check-and-balance in many organizations and they should routinely review the work of both their own teams and others. Management reviews play two important roles in the security process. First, they provide an important double check on the work performed by employees to verify accuracy and completeness. Second, they reduce fraud and malfeasance by creating a culture of oversight. If employees, particularly privileged users, know that someone is checking their work, they will be far less likely to engage in unscrupulous activity. Privileged actions are the most important tasks requiring management review. System engineers, application administrators, and other trusted employees often have the ability to override normal security controls and perform actions that would…