Skip to content

CMA Final · Cost and Management Audit · Information Systems Security Audit

During an IS security audit at a manufacturing company in Pune, the auditor finds that several former employees' user IDs remain active in the ERP system months after their exit. Which risk is most directly heightened by this finding?

The finding most directly raises the risk of unauthorised access and fraudulent transactions. Active user IDs of former employees are a weakness in logical access control, because anyone holding those credentials can view or alter ERP data without authorisation. Hardware, depreciation and bandwidth issues are unrelated.

  1. AUnauthorised access and possible fraudulent transactions through dormant accountsCorrect
  2. BLoss of data due to hardware failure at the primary server
  3. CInaccurate depreciation computation caused by wrong asset lives
  4. DDelay in backup scheduling due to network bandwidth limits

Explanation

Active IDs of ex-employees are a logical access weakness. They can be misused by the former employee or others to access or alter data. The other options relate to hardware, accounting parameters or network capacity, which are not connected to user ID management.

Did you get it right without looking?

One question tells you little. A timed set on Information Systems Security Audit shows your real accuracy, how long you take and where you lose marks.

More Information Systems Security Audit questions