Question

Difficulty: MediumData Security and Threats in Accounting Systems

A financial controller discovered that a junior clerk modified posted general ledger entries despite only being authorized to process purchase orders. Which internal IT control mechanism should have been enforced to restrict the clerk's system privileges strictly to assigned job functions?

  1. Role-based access controlAnswer
  2. B
    Offsite data backup procedures
  3. C
    Antivirus software scheduling
  4. D
    Network firewall filtering

Answer

Role-based access control
Role-based access control ensures that each system user is granted only the rights necessary to perform their designated job duties. Restricting the junior clerk's access to the purchase order module prevents unauthorized editing of the general ledger.

Step-by-Step Solution

1
Analyze the security breach scenario
Identified that an internal authenticated user performed unauthorized actions beyond their job scope.
Understanding the nature of the security gap distinguishes internal privilege management from external threat defense.
2
Evaluate candidate IT control measures
Determined that restricting user capabilities according to specific job roles directly prevents unauthorized module access.
Role-based access control enforces the principle of least privilege in accounting information systems.

Key Concept

Role-Based Access Control and Internal Security Controls
Rate this question