CompTIA Data+ (DA0-002)Data Governance, Quality and ControlsHard
To reduce the risk of fraud, a company requires that the employee who initiates a vendor payment record cannot be the same employee who approves that payment for processing. This control is an example of which governance principle?
- ALeast privilege
- BData minimization
- CRole escalation
- DSeparation of duties
Show answer & explanationAnswer & explanation
Correct answer: D. Separation of duties
Separation of duties requires that critical tasks, such as initiating and approving a transaction, be divided among different individuals to prevent a single person from committing and concealing fraud or error.
Why the other options are wrong
- A. Least privilege limits each user's access to only what is needed, but does not specifically require splitting tasks between two people.
- B. Data minimization limits the amount of data collected, unrelated to task division.
- C. Role escalation is not a recognized governance control principle; it is a distractor term.
Separation of Duties (SoD)
A control principle that divides critical tasks, such as authorization, execution, and review, among multiple individuals to reduce the risk of fraud or error.
- Prevents any single person from controlling an entire process
- Commonly applied to financial transactions and approvals
- Complements least privilege but focuses on task division, not access scope
Memory trick: No one person should both write the check and sign it.