ERP Security, Access Control & Role-Based Permissions Flashcards
7 cards from real ERP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 ERP Security, Access Control & Role-Based Permissions flashcards as text
What is the recommended approach when designing roles in an ERP RBAC system?
Answer: Create roles based on job functions shared by multiple users
Roles should be designed around job functions, allowing multiple users with the same responsibilities to share a common, maintainable role.
During ERP implementation, what is a 'role matrix'?
Answer: A document mapping job positions to the system roles and permissions required
A role matrix maps each organizational job position to its corresponding system roles and specific permissions, serving as the governance foundation for access control design.
What is the biggest security risk associated with 'role bloat' in ERP systems?
Answer: Users accumulate excessive permissions over time, violating least privilege
Role bloat occurs when users accumulate roles and permissions beyond what they need, creating security violations and SoD conflicts that increase fraud risk.
What is 'role inheritance' in ERP access control design?
Answer: A hierarchical structure where child roles inherit permissions from parent roles
Role inheritance allows child roles to automatically inherit permissions from parent roles, enabling efficient management of layered permission hierarchies.
What is a 'composite role' in SAP ERP security terminology?
Answer: A container that groups multiple single roles together for easier user assignment
A composite role in SAP groups multiple single roles into one container, allowing efficient assignment of a complete set of permissions needed for a job function.
What is 'provisioning' in the context of ERP user account management?
Answer: The process of granting, modifying, or revoking user access rights
Provisioning refers to the lifecycle management of user access rights—granting access when hired, modifying upon role changes, and revoking upon termination.
When should user access rights be formally reviewed in an ERP environment?
Answer: Annually and whenever an employee changes job roles or responsibilities
Access rights should be reviewed at least annually and immediately upon any role change to ensure permissions remain appropriate, current, and compliant.