Certified Information Systems Auditor (CISA) — Question 1413
A company has implemented an IT segregation of duties policy. In a role-based environment, which of the following roles may be assigned to an application developer?
Answer options
- A. Emergency support
- B. System administration
- C. IT operator
- D. Database administration
Correct answer: A
Explanation
The correct answer is A, Emergency support, as this role typically allows for immediate response without compromising segregation of duties. In contrast, roles like System administration, IT operator, and Database administration involve higher levels of access and responsibility that could conflict with the principles of segregation of duties.