XML Feeds

Search Big4Guy

Custom Search

Sponsored

« Authorization Description Profile Name - SAP ECC Enterprise Controlling Authorization Profiles ExamplesAuditing Standard 4 Reporting on whether a Previously Reported Material Weakness Continues to Exist »

Seperation of Duties in IT Environment - CISA Questions

Seperation of Duties in IT Environment - CISA Questions

Which of the following are functions that are compatible in a properly segregated environment?

a) Systems programming and job control analysis.
b) Access authorization and database administration.
c) System development and systems maintenance.
d) Application programming and computer operation.

Answer: the correct answer is "C". The main aim of segregation of duties is to ensure that no single individual can compromise an application system's features and its control functions. In a IT environment, it is common for system development and maintenance to be undertaken by the same person. In such cases the programmer requires access to the source code in the development environment, but should not be allowed access in the production environment. A computer operator should not have the possibility of modifying applications because they already have access to all resources of the systems and that would allow them to introduce fraudulent changes. Systems programming is incompatible with job control analysis since a systems programmer could change the job control parameters to run their own personal jobs. Access authorization is a responsibility of data owners, not database administrators.

Related CISA Exam Questions

Quantitative Risk Analysis
Statistical Sampling
Retention Date for Files
Disaster Recovery Hot Site


Permalink 07/16/06 11:38:15 am , by big4guy Email , 720 views, CISA Exam, Leave a comment »

Feedback awaiting moderation

This post has 42 feedbacks awaiting moderation...

Leave a comment


Your email address will not be revealed on this site.

Your URL will be displayed.
(Line breaks become <br />)
(Name, email & website)
(Allow users to contact you through a message form (your email will not be revealed.)