CMA Final · Cost and Management Audit · Information Systems Security Audit
An auditor reviewing a company's ERP finds that the same employee can create a vendor master record, approve purchase orders to that vendor and release payment. Which security principle is primarily violated?
Segregation of duties is violated, because one employee can create a vendor, approve purchase orders and release payment. Splitting incompatible functions among different people prevents a single person from committing and concealing fraud, which is the core purpose of this access control.
- ASegregation of dutiesCorrect
- BData encryption in transit
- CBusiness continuity planning
- DVersion control of source code
Explanation
Creating vendors, approving orders and releasing payments should be assigned to different people so that no one can commit and conceal fraud. Giving all three to one user breaks segregation of duties. Encryption, continuity and version control address different risks and are not the issue described.
Did you get it right without looking?
One question tells you little. A timed set on Information Systems Security Audit shows your real accuracy, how long you take and where you lose marks.
More Information Systems Security Audit questions
- In an information systems security audit, which control is a preventive control rather than a detective or corrective one?
- In an information systems security audit, which control is a preventive control designed to stop unauthorised persons from entering a payrol…
- Which of the following best describes the 'integrity' objective in the confidentiality-integrity-availability model used in information secu…
- An auditor reviewing a payroll application wants to verify that the program logic computes deductions correctly, by processing the auditor's…
- Which of the following best describes a 'hot site' in a disaster recovery arrangement?
- Which of the following is an example of a logical access control, as distinct from a physical access control?