ISO 27001's Annex A control A.6.1.2 requires segregation of duties. Which scenario BEST demonstrates a violation of this control?
-
A
A developer writes code that is reviewed by a separate QA team
-
B
A system administrator both requests and approves privileged access for themselves
-
C
A security officer reports ISMS status to the board
-
D
Two employees share responsibilities for reviewing security logs