A county court hosts sealed juvenile records that must stay available only to authorized staff. Which access approach correctly addresses both information and systems?
Select an answer to reveal the explanation.
Short Explanation
Sealed juvenile files need both a locked room and a locked login—one without the other is a half-closed vault. Pair ACLs and authenticated accounts on the system with physical controls on the room or media. Open LAN apps, public postings, or “badge equals login” leave a gap.
Full Explanation
CISSP Domain 5 requires controlling physical and logical access to information and systems together. Sensitive repositories such as sealed juvenile records need authenticated, authorization-enforced application and data permissions plus facility controls that limit who can approach servers, workstations, or offline media. Physical entry alone does not stop lateral LAN access, and removing authentication because badges exist conflates facility identity with system identity. Public disclosure of sealed content violates confidentiality requirements regardless of building locks.