Skip to content

CMA Final · Cost and Management Audit · Information Systems Security Audit

An auditor reviewing a company's ERP finds that the same employee can create a vendor master record, approve purchase orders to that vendor and release payment. Which security principle is primarily violated?

Segregation of duties is violated, because one employee can create a vendor, approve purchase orders and release payment. Splitting incompatible functions among different people prevents a single person from committing and concealing fraud, which is the core purpose of this access control.

  1. ASegregation of dutiesCorrect
  2. BData encryption in transit
  3. CBusiness continuity planning
  4. DVersion control of source code

Explanation

Creating vendors, approving orders and releasing payments should be assigned to different people so that no one can commit and conceal fraud. Giving all three to one user breaks segregation of duties. Encryption, continuity and version control address different risks and are not the issue described.

Did you get it right without looking?

One question tells you little. A timed set on Information Systems Security Audit shows your real accuracy, how long you take and where you lose marks.

More Information Systems Security Audit questions