Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Enterprise Resource Management

A company's ERP holds employees' personal and bank details. A disgruntled insider with excessive access rights copies the payroll data and sells it. Which ERP risk is primarily exposed, and which Indian law principle is most relevant?

The risk is weak access control and segregation of duties, which let an insider misuse centralised data. The relevant law is the IT Act provisions on unauthorised access and data theft, along with data protection obligations on personal data.

  1. AVendor lock-in; Indian Contract Act principles on consideration
  2. BWeak segregation of duties and access control; data protection and IT Act provisions on unauthorised access and data theftCorrect
  3. CHardware obsolescence; Companies Act provisions on dividends
  4. DPoor user training; Sale of Goods Act

Explanation

Excessive access rights reflect weak role-based access and segregation of duties, a core ERP security risk. Copying data without permission engages IT Act offences on unauthorised access and data theft, together with data protection obligations. The other options pair unrelated risks and laws.

Did you get it right without looking?

One question tells you little. A timed set on Enterprise Resource Management shows your real accuracy, how long you take and where you lose marks.

More Enterprise Resource Management questions