Which artifact defines who has access to which resources?

Prepare for the Trusted Agent Module 2 Exam. Engage with in-depth quizzes featuring flashcards and multiple-choice questions. Each question comes with hints and detailed explanations to enhance your learning. Equip yourself for exam success!

Multiple Choice

Which artifact defines who has access to which resources?

Explanation:
Access decisions are anchored in the access control policy. This document states who may access which resources, under what conditions, and the privileges required to perform certain actions. It sets the authoritative rules, guiding how access is granted, reviewed, and revoked across all systems. The authorization matrix is a practical tool that implements those rules in a specific view (mapping users or roles to permissions on resources), but the policy itself defines the rights and constraints that everything else follows. A data classification scheme helps determine handling based on data sensitivity, not who is allowed to access it. An incident response plan covers steps to take during security incidents, not day-to-day access rights.

Access decisions are anchored in the access control policy. This document states who may access which resources, under what conditions, and the privileges required to perform certain actions. It sets the authoritative rules, guiding how access is granted, reviewed, and revoked across all systems. The authorization matrix is a practical tool that implements those rules in a specific view (mapping users or roles to permissions on resources), but the policy itself defines the rights and constraints that everything else follows. A data classification scheme helps determine handling based on data sensitivity, not who is allowed to access it. An incident response plan covers steps to take during security incidents, not day-to-day access rights.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy