ISC Exam Questions

The ability of one person in the fi nance department to add vendors to the vendor database and subse

The ability of one person in the fi nance department to add vendors to the vendor database and subsequently pay the vendor violates which concept?

A.
A well-formed transaction

B.
Separation of duties

C.
Job rotation

D.
Data sensitivity level

Explanation:
B: One individual should not have the capability to execute all of the steps of a particular process. Th is is especially important in critical business areas, where individuals may have greater access and capability to modify, delete, or add data to the system. Page 441.