ERP Security, Access Control & Role-Based Permissions Flashcards
7 cards from real ERP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 ERP Security, Access Control & Role-Based Permissions flashcards as text
What is the primary purpose of an ERP system audit trail?
Answer: To provide a chronological record of user actions for accountability and investigation
Audit trails record who did what and when in the system, enabling accountability, forensic investigation, and verification of compliance with internal controls.
Which US regulation most directly impacts access control and audit trail requirements in ERP systems used by publicly traded companies?
Answer: SOX (Sarbanes-Oxley Act)
SOX requires publicly traded companies to maintain internal controls over financial reporting, which directly mandates ERP access controls, SoD enforcement, and audit trails.
In ERP security governance, what does the acronym 'GRC' stand for?
Answer: Governance, Risk, and Compliance
GRC (Governance, Risk, and Compliance) in ERP context refers to integrated tools and processes for managing organizational policies, risk assessment, and regulatory compliance requirements.
What is a 'User Access Review' (UAR) in ERP governance?
Answer: A periodic process where managers certify that their employees' access rights remain appropriate
A UAR is a formal governance process where business managers review and certify that each employee's system access remains appropriate and necessary for their current role.
What is a 'compensating control' in the context of an ERP SoD conflict?
Answer: An alternative control that mitigates risk when an SoD conflict cannot be immediately eliminated
Compensating controls are alternative mitigations such as enhanced monitoring or mandatory managerial approval applied when ideal SoD separation is not immediately achievable.
What is the recommended course of action when an ERP security audit identifies an SoD conflict for a specific user?
Answer: Document the conflict, assess the risk, assign a compensating control, and then remediate
SoD conflicts should be documented and risk-assessed; compensating controls can mitigate risk while remediation through role redesign eliminates the root conflict.
Which capability is most critical in an ERP GRC solution for proactively managing Segregation of Duties risks?
Answer: Real-time SoD conflict detection with preventive role assignment controls
GRC solutions provide real-time SoD conflict detection during role assignment, preventing users from receiving incompatible permission combinations before access is ever granted.