PrepAway - Latest Free Exam Questions & Answers

Which of the following controls would an IS auditor loo…

Which of the following controls would an IS auditor look for in an environment where duties cannot
be appropriately segregated?

PrepAway - Latest Free Exam Questions & Answers

A.
Overlapping controls

B.
Boundary controls

C.
Access controls

D.
Compensating controls

Explanation:
Compensating controls are internal controls that are intended to reduce the risk of an existing or
potential control weakness that may arise when duties cannot be appropriately segregated.
Overlapping controls are two controls addressing the same control objective or exposure. Since
primary controls cannot be achieved when duties cannot or are not appropriately segregated, it is
difficult to install overlapping controls. Boundary controls establish the interface between the wouldbe user of a computer system and the computer system itself, and are individual-based, not rolebased, controls. Access controls for resources are based on individuals and not on roles.


Leave a Reply