QuestionQ39

Security Architecture

An organization wants to implement an access control system based on its data classification policy that includes the following data types:

Confidential -

Restricted -

Internal -

Public Flag for Review -

The access control system should support SSO federation to map users into groups. Each group should only access systems that process and store data at the classification assigned to the group. Which of the following should the organization implement to enforce its requirements with a minimal impact to systems and resources?

Explanation

Because the SSO federation already groups users, mapping those existing groups to internal roles tied to a human resources source of truth lets access be granted at the role level with essentially no per-resource configuration, satisfying the requirement for minimal impact to systems and resources. A tagging-plus-ABAC scheme requires classifying and tagging every individual resource and building attribute-evaluation logic, microsegmentation requires rearchitecting the network, and LDAP-managed rules applied per system require touching each system individually — all of which impose far greater operational overhead than reusing HR-sourced role assignments.

Community Discussion

No comments yet. Be the first to start the discussion!