ExamGecko
Question list
Search
Search

Related questions











Question 320 - CISA discussion

Report
Export

A company has implemented an IT segregation of duties policy. In a role-based environment, which of the following roles may be assigned to an application developer?

A.
IT operator
Answers
A.
IT operator
B.
System administration
Answers
B.
System administration
C.
Emergency support
Answers
C.
Emergency support
D.
Database administration
Answers
D.
Database administration
Suggested answer: C

Explanation:

Segregation of duties (SOD) is a core internal control and an essential component of an effective risk management strategy.SOD emphasizes sharing the responsibilities of key business processes by distributing the discrete functions of these processes to multiple people and departments, helping to reduce the risk of possible errors and fraud1.

SOD is especially important in IT security, where granting excessive system access to one person or group can lead to harmful consequences, such as data breaches, identity theft, or bypassing security controls2.SOD breaks IT-related tasks into four separate function categories: authorization, custody, recordkeeping, and reconciliation1. Ideally, no one person or department holds responsibility in multiple categories.

In a role-based environment, where access privileges are granted based on predefined roles, it is important to ensure that the roles are designed and assigned in a way that supports SOD. For example, the person who develops an application should not also be the one who tests it, deploys it, or maintains it.

Therefore, an application developer should not be assigned the roles of IT operator, system administration, or database administration, as these roles may conflict with their development role and create opportunities for misuse or abuse of the system.The only role that may be assigned to an application developer without violating SOD is emergency support, which is a temporary role that allows the developer to access the system in case of a critical issue that requires immediate resolution3. However, even this role should be granted with caution and monitored closely to ensure compliance with SOD policies.

ISACA, CISA Review Manual, 27th Edition, 2019, page 2824

ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription, QID 1066692

Hyperproof Blog, Segregation of Duties: What it is and Why it's Important1

Advisera Blog, Segregation of duties in your ISMS according to ISO 27001 A.6.1.23

asked 18/09/2024
Janson Chong
26 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first