Attempt Latest Update with Complete Solution
VUN1 — VUN1 Task 1: Managing Security Operations and Access Controls
Information Systems Security - C845
A. Apply an Access Control Model
A.1. Chosen Access Control Model
I have chosen the Role-Based Access Control (RBAC) model. The principles of RBAC are:
• Role Assignment: A user is assigned to a role based on their job function (e.g., "Finance
Analyst").
• Permission Assignment: Permissions to perform operations on systems are assigned to roles,
not to individual users.
• Session Management: A user activates a role to gain the associated permissions for a session.
• Least Privilege: Users should only have the minimum level of access necessary to perform their
job duties.
The organization's access control structure, as seen in the user matrix, is implicitly role-based (e.g.,
"Finance manager," "HR coordinator"). Applying a formal RBAC model would streamline this by ensuring
permissions are strictly tied to business functions, reducing complexity and the potential for user error
when assigning permissions.
A.2. Four Misalignments with RBAC Principles
1. Misalignment 1: Privilege Escalation Beyond Role Scope
• Description: The "Junior system admin" (J. Lopez) has "Domain admin" privileges. A
junior role should not have the highest level of access in a Windows environment.
, lOMoAR cPSD| 67928686
• Conflict with RBAC: This violates the principle of least privilege. The role "Junior system
admin" implies a subset of administrative duties, not unrestricted domain-wide control.
2. Misalignment 2: Unnecessary Access Across Departments
• Description: The "Finance analyst" (L. Cheng) has "Full access" to the CRM, a system
primarily for Sales and Support. A finance role typically does not require full modification rights
in a customer relationship system.
• Conflict with RBAC: This violates least privilege and separation of duties. It allows for
potential data manipulation outside the user's core business function.
3. Misalignment 3: Violation of User-Role Assignment Post-Termination
• Description: The "HR assistant" (P. Ellis), who was terminated on 2025-05-20, has an
"Active" account status and successfully logged in on 2025-06-29.
• Conflict with RBAC: RBAC requires timely revocation of role assignments upon a change
in employment status. An active session for a terminated user completely bypasses the
security provided by the role structure.
4. Misalignment 4: Overly Broad Privileged Access
• Description: The "IT administrator" (T. Miller) has "Full admin" access to "All internal
systems," and the log shows they made a firewall rule change without a ticket_id.
• Conflict with RBAC: While some access is necessary, blanket "Full admin" access violates
least privilege and impedes accountability. It does not segment duties within the IT
department itself.
A.3. Recommended Changes to Resolve Misalignments
nj nj nj nj
1. Recommendation 1:Implement njPrivilegeTieringforAdministrativeRoles
j
• Justification: njFollowing njthe njCIS njControl nj5 nj(Account njManagement) njand njthe njprinciple
of
nj
nj least privilege,administrativeaccounts shouldbesegregated.The"Juniorsystemadmin"
j j
, nj role njshould njbe njassigned njamorerestricted njsetofprivileges, njsuch njas nj"Server
nj Operator" njor nj"Help njDesk njAdministrator," njwhich njallows njfor njdaily njtasks
nj without njgranting njdomain-wide njcontrol nj(NIST njSP nj800-53, njAC-6).
2. Recommendation 2:Conduct aRole-PermissionReview n j andRemediation
j j
• Justification: njAlign njwith njISO/IEC nj27001:2022, njA.5.35 nj(Access njcontrol) njby njperforming
a njformal njreviewofall njrole njassignments.Remove njaccessto
nj
nj systemslikethe nj CRM from
nj the
nj
nj "Financeanalyst"role unlessacompellingbusinessjustificationexists.Accessshouldbe
j
nj based njon njdocumented njjob njrequirements.
3. Recommendation 3:AutomateAccess RevocationandEnforceChangeManagement •
j j
Justification:PerNISTSP800-53,AC-2(Account Management),accountrevocationmust
j
nj occur njimmediately njupon njtermination. njThis njshould njbe njan njautomated njpart njof njthe
nj HR offboarding
nj nj process. Furthermore,
nj all
nj changes,
nj including
nj firewall
nj
nj modifications, njmust njrequire njaticket njID njfor njapprovalnj and njauditing nj(CIS njControl nj10
nj nj- Malware njDefenses, njrelying njon njchange njmanagement).
A.4. Revised User Role Matrix
nj nj nj
Therevisedmatrixreflects astricterRBACimplementation.Keychangesare n j bolded.
j
Role Assigned njUser SystemAccess PrivilegeLevel(Revised)
Finance njManager A. njJones Payrollsystem,budget Fullaccess
tracker
nj
Financeanalyst L. njCheng Payrollsystem,budget Readandwrite(CRM
tracker
nj nj access njremoved)
HR njcoordinator M.Singh HRportal,payroll njsystem Readandwrite
Security njAnalyst K. njPatel SIEM,networklogs, Readonly
nj firewallconsole