Mechanisms exist to ensure security functions are restricted to authorized individuals and enforce least privilege control requirements for necessary job functions.
Does the organization ensure security functions are restricted to authorized individuals and enforce least privilege control requirements for necessary job functions?