Page 143 - (ISC)² CISSP Certified Information Systems Security Professional Official Study Guide
P. 143

FIGURE 2.2 An example of job rotation among management
               positions


               Second, moving personnel around reduces the risk of fraud, data
               modification, theft, sabotage, and misuse of information. The longer a
               person works in a specific position, the more likely they are to be
               assigned additional work tasks and thus expand their privileges and
               access. As a person becomes increasingly familiar with their work
               tasks, they may abuse their privileges for personal gain or malice. If

               misuse or abuse is committed by one employee, it will be easier to
               detect by another employee who knows the job position and work
               responsibilities. Therefore, job rotation also provides a form of peer
               auditing and protects against collusion.
   138   139   140   141   142   143   144   145   146   147   148