A financial controller discovered that a junior clerk modified posted general ledger entries despite only being authorized to process purchase orders. Which internal IT control mechanism should have been enforced to restrict the clerk's system privileges strictly to assigned job functions?
- Role-based access controlAnswer
- BOffsite data backup procedures
- CAntivirus software scheduling
- DNetwork firewall filtering
Answer
Role-based access control
Role-based access control ensures that each system user is granted only the rights necessary to perform their designated job duties. Restricting the junior clerk's access to the purchase order module prevents unauthorized editing of the general ledger.
Step-by-Step Solution
Key Concept
Role-Based Access Control and Internal Security Controls