Question

Difficulty: EasyData Security and Threats in Accounting Systems

An accounting firm wishes to restrict access to confidential ledger records so that staff members can only view data necessary for their specific job roles. Which of the following internal control measures best achieves this objective?

  1. Implementing role-based user access permissions and authenticationAnswer
  2. B
    Installing automated antivirus scanning software on all network workstations
  3. C
    Switching transaction entry from real-time processing to periodic batch processing
  4. D
    Performing routine off-site data backups at the end of each financial period

Answer

Implementing role-based user access permissions and authentication
Implementing role-based user access permissions ensures logical access security by restricting user accounts to only the specific accounting files, functions, and reports required for their assigned duties.

Step-by-Step Solution

1
Identify the primary threat or vulnerability described in the scenario.
The requirement is to prevent unauthorized internal access to confidential accounting ledgers by restricting employees to job-relevant data.
Internal security controls in computerized accounting require restricting system access according to authorization levels.
2
Evaluate the listed security controls to match the specific requirement.
Role-based access control directly enforces authorization limits by assigning specific viewing and editing permissions to user profiles.
Other security controls, such as antivirus software or backups, address external malware and data loss rather than internal access authorization.

Key Concept

Logical Access Controls and User Authorization in Accounting Systems
Rate this question