Print this Page

Separation Of Privilege

When at all possible it is a far more robust and secure to require two security controls to unlock something rather than just require a single control. This allows to separate the privileges between two controls/parties/programs, etc. This ensures that no single breach of a security control would cause problems of catastrophic consequences.
Example: Authentication system that requires two or more conditions needing to be met to access a system such as password and answer to security questions.

Main Menu

Permanent link to this article: http://blogs.cae.tntech.edu/secknitkit/separation-of-privilege/