ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITEasy
A CISA is auditing an organization's IT organizational structure. The CISA observes that the database administrators (DBAs) also have full administrative access to the operating systems and network devices that host the databases. What is the MOST significant concern from an IT governance perspective?
- AIt increases the complexity of incident response procedures.
- BIt makes it difficult to implement effective patch management.
- CIt creates a single point of failure for critical systems.
- DIt violates the principle of segregation of duties (SoD).
Show answer & explanationAnswer & explanation
Correct answer: D. It violates the principle of segregation of duties (SoD).
Giving DBAs administrative access to the underlying operating systems and network devices violates segregation of duties, as it concentrates too much control in one role, increasing the risk of fraud, error, or malicious activity without detection.
Why the other options are wrong
- A. While complexity might increase, the primary governance concern is control and accountability.
- B. Patch management is an operational concern; the fundamental governance issue here is the lack of proper control separation.
- C. While a single person having multiple critical access rights is a risk, the core principle being violated is SoD, which aims to prevent this concentration of power.
Segregation of Duties (SoD)
Segregation of Duties (SoD) is an internal control designed to prevent fraud and errors by ensuring that no single individual has complete control over a critical process or system.
- Separates conflicting responsibilities.
- Reduces risk of unauthorized actions.
- Requires multiple individuals for a complete transaction.
Memory trick: Separate duties to 'STOP' fraud: Segregation, Transparency, Oversight, Prevention.