CPA · Question 05 · Area I: Information Systems
During a walkthrough of the change management process, an auditor observes that the 'Developer' role in the ERP system has access to 'Migrate to Production'. The IT Manager explains this is necessary for emergency fixes overnight when the Change Manager is unavailable. What is the auditor's BEST course of action?
Answer options:
Accept the explanation as a valid business requirement.
Recommend that the Developer role be removed entirely.
Identify this as a Segregation of Duties (SoD) deficiency and recommend a separate 'Emergency ID' with monitoring.
Require that the Change Manager work overnight shifts.
82 questions · hints · full answers · grading