Which of the following is a MAJOR concern for the IS auditor? WHY?

Computer Networking: A Top-Down Approach (7th Edition)
7th Edition
ISBN:9780133594140
Author:James Kurose, Keith Ross
Publisher:James Kurose, Keith Ross
Chapter1: Computer Networks And The Internet
Section: Chapter Questions
Problem R1RQ: What is the difference between a host and an end system? List several different types of end...
icon
Related questions
Question
100%

CASE STUDY B

An organization has implemented an integrated application for supporting business processes. It has also entered into an agreement with a vendor for application maintenance and providing support to the users and system administrators. This support will be provided by a remote vendor support center using a privileged user ID with OS-level superuser authority having read and write access to all files. The vendor will use this special user ID to log on to the system for troubleshooting and implementing application updates (patches). Due to the volume of transactions, activity logs are only maintained for 90 days.

Questions

Select the letter of your best answer and provide further explanation to elaborate on your answer.

  1. Which of the following is a MAJOR concern for the IS auditor? WHY?
  1. User activity logs are only maintained for 90 days.
  2. The special user ID will access the system remotely.
  3. The special user ID can alter activity log files.
  4. The vendor will be testing and implementing patches on servers.
  1. Which of the following actions would be MOST effective in reducing the risk that the privileged user account

may be misused? WHY?

  1. The special user ID should be disabled except when maintenance is required.
  2. All usage of the special user account should be logged.
  3. The agreement should be modified so that all support is performed onsite.
  4. All patches should be tested and approved prior to implementation.
Expert Solution
trending now

Trending now

This is a popular solution!

steps

Step by step

Solved in 2 steps

Blurred answer
Recommended textbooks for you
Computer Networking: A Top-Down Approach (7th Edi…
Computer Networking: A Top-Down Approach (7th Edi…
Computer Engineering
ISBN:
9780133594140
Author:
James Kurose, Keith Ross
Publisher:
PEARSON
Computer Organization and Design MIPS Edition, Fi…
Computer Organization and Design MIPS Edition, Fi…
Computer Engineering
ISBN:
9780124077263
Author:
David A. Patterson, John L. Hennessy
Publisher:
Elsevier Science
Network+ Guide to Networks (MindTap Course List)
Network+ Guide to Networks (MindTap Course List)
Computer Engineering
ISBN:
9781337569330
Author:
Jill West, Tamara Dean, Jean Andrews
Publisher:
Cengage Learning
Concepts of Database Management
Concepts of Database Management
Computer Engineering
ISBN:
9781337093422
Author:
Joy L. Starks, Philip J. Pratt, Mary Z. Last
Publisher:
Cengage Learning
Prelude to Programming
Prelude to Programming
Computer Engineering
ISBN:
9780133750423
Author:
VENIT, Stewart
Publisher:
Pearson Education
Sc Business Data Communications and Networking, T…
Sc Business Data Communications and Networking, T…
Computer Engineering
ISBN:
9781119368830
Author:
FITZGERALD
Publisher:
WILEY