Skip to content

ACCA Strategic Professional · Strategic Business Leader · IT systems security and control

Kestrel Logistics has found that a developer who writes changes to its inventory system can also move those changes into the live environment without review. Management wants a control that addresses this weakness. Which IT general control category does the weakness fall under, and what is the appropriate remedy?

It is a program change management weakness in IT general controls. The fix is to separate development from production migration and require independent testing and approval, so no single developer can alter live code without review.

  1. AProgram change management; separate development from migration to production and require independent approvalCorrect
  2. BInput validation; add a limit check to the stock quantity field
  3. COutput review; reconcile printed reports to source documents
  4. DPhysical security; fit biometric locks to the server room

Explanation

Allowing a developer to push unreviewed changes to live systems is a program change weakness within general controls. The remedy is segregation between development and production, with independent authorisation and testing. Input validation is an application control and would not stop unauthorised code changes.

Did you get it right without looking?

One question tells you little. A timed set on IT systems security and control shows your real accuracy, how long you take and where you lose marks.

More IT systems security and control questions