CISA · Question #623
An IS auditor has identified that as users change departments or leave the company, their access is not adjusted. Which of the following would BEST help to address this situation?
The correct answer is B. Perform periodic access recertification. Periodic access recertification requires managers to regularly review and formally validate that each user's access rights are still appropriate for their current role. This directly addresses the problem of stale or excessive access accumulating over time as employees change…
Question
An IS auditor has identified that as users change departments or leave the company, their access is not adjusted. Which of the following would BEST help to address this situation?
Options
- APublish user access management policies.
- BPerform periodic access recertification.
- CAssign user administration rights to line management.
- DMandate periodic password changes.
How the community answered
(18 responses)- A6% (1)
- B83% (15)
- D11% (2)
Explanation
Periodic access recertification requires managers to regularly review and formally validate that each user's access rights are still appropriate for their current role. This directly addresses the problem of stale or excessive access accumulating over time as employees change departments or leave. Publishing policies (A) creates awareness but does not enforce action. Delegating admin rights to line managers (C) may help but without a recertification process, access still may not be removed promptly. Password changes (D) address authentication strength, not authorization scope.
Topics
Community Discussion
No community discussion yet for this question.