From the course: CISSP Cert Prep (2021): 6 Security Assessment and Testing

Unlock the full course today

Join today to access over 22,400 courses taught by industry experts or purchase this course individually.

Management review and approval

Management review and approval

From the course: CISSP Cert Prep (2021): 6 Security Assessment and Testing

Start my 1-month free trial

Management review and approval

- [Instructor] IT and security managers have some key responsibilities when it comes to operational security controls. Managers serve as a critical check-and-balance in many organizations and they should routinely review the work of both their own teams and others. Management reviews play two important roles in the security process. First, they provide an important double check on the work performed by employees to verify accuracy and completeness. Second, they reduce fraud and malfeasance by creating a culture of oversight. If employees, particularly privileged users, know that someone is checking their work, they will be far less likely to engage in unscrupulous activity. Privileged actions are the most important tasks requiring management review. System engineers, application administrators, and other trusted employees often have the ability to override normal security controls and perform actions that would…

Contents