An IS auditor identifies that an accounts payable clerk has direct access to a payment file after it has been generated. The MOST significant risk to the organization is that payments may be:
An IS auditor identifies that an accounts payable clerk has direct access to a payment file after it has been generated. The MOST significant risk to the organization is that payments may be:
SoD principle is violated here. The same person shouldnt have access to both of those actions. this introduces things like fraud. C is correct. Altered.