A municipality protects both a data-center cage and a public library self-checkout kiosk. How should access-control strength be applied?
Select an answer to reveal the explanation.
Short Explanation
A server cage and a checkout kiosk are not the same treasure chest. Put heavy MFA, escort, and monitoring on the cage, and use lighter but still deliberate controls on the public kiosk. One-size mantraps everywhere, unlocking the cage because the library uses PINs, or deleting logs ignore asset risk.
Full Explanation
Defense of assets under IAM expects control intensity to reflect asset value, exposure, and threat. Data-center cages typically warrant strong physical authentication, monitoring, and escorted entry, whereas public kiosks need controls that limit tampering and privilege without blocking citizen use. Uniform extreme controls on low-sensitivity assets waste resources, and weakening cage protections to match a kiosk underprotects critical systems. Logging remains necessary for accountability across asset types.