ACCA Strategic Professional · Strategic Business Leader · IT systems security and control
Kestrel Logistics has found that a developer who writes changes to its inventory system can also move those changes into the live environment without review. Management wants a control that addresses this weakness. Which IT general control category does the weakness fall under, and what is the appropriate remedy?
It is a program change management weakness in IT general controls. The fix is to separate development from production migration and require independent testing and approval, so no single developer can alter live code without review.
- AProgram change management; separate development from migration to production and require independent approvalCorrect
- BInput validation; add a limit check to the stock quantity field
- COutput review; reconcile printed reports to source documents
- DPhysical security; fit biometric locks to the server room
Explanation
Allowing a developer to push unreviewed changes to live systems is a program change weakness within general controls. The remedy is segregation between development and production, with independent authorisation and testing. Input validation is an application control and would not stop unauthorised code changes.
Did you get it right without looking?
One question tells you little. A timed set on IT systems security and control shows your real accuracy, how long you take and where you lose marks.
More IT systems security and control questions
- Orion Retail sends customer order files to a payment processor over the internet. Management wants assurance that only the processor can rea…
- Lindqvist Media gives staff access to systems based on job role, so a new marketing analyst automatically receives the same permissions as o…
- Halden Logistics has suffered two phishing incidents this year. The board has so far treated cyber security as a technical matter for the IT…
- Lumen Telecom wants to launch an app using customer location data. Before design begins, the CIO insists on assessing privacy risks and buil…
- Altamira Bank's board states that, after a system failure, payment processing must be restored within 2 hours, and that no more than 15 minu…
- Zenith Insurance allows staff to work remotely. The risk committee proposes that access to claims data be granted only after checking user i…