QuestionQ19

Data mobility, protection, and replication for unstructured data

Which security control should a sales engineer point to in order to address concerns about the risk posed by administrators to backup data?

Explanation

Dual authorization (also referred to as quorum or multi-person authorization) requires that any root-level or otherwise critical/sensitive operation on backup data — such as deleting snapshots, disabling protection policies, or altering retention/security settings — be approved by more than one authorized person before it can be executed. This directly mitigates the risk of a single rogue, poorly trained, or compromised administrator unilaterally causing loss or corruption of backup data, which is the essence of 'administrative risk.' Role-based access control only defines what actions a given user/role is permitted to perform and does not stop an already-privileged single administrator from acting alone, and Secure Boot with TPM 2.0 addresses firmware/hardware boot integrity rather than administrative operational risk.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!