ERP Security, Access Control & Role-Based Permissions Flashcards
7 cards from real ERP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 ERP Security, Access Control & Role-Based Permissions flashcards as text
What is the primary purpose of Role-Based Access Control (RBAC) in an ERP system?
Answer: To assign system permissions based on a user's job function
RBAC assigns permissions based on job roles, ensuring users access only the data and functions relevant to their responsibilities.
In ERP security, what does 'Segregation of Duties' (SoD) primarily prevent?
Answer: Fraud and errors by ensuring no single user controls an entire critical process
SoD ensures that critical transactions require involvement from multiple users, preventing any one person from committing and concealing fraud.
What does the 'principle of least privilege' mean in ERP security?
Answer: Users should have the minimum access needed to perform their job duties
Least privilege limits user access rights to only what is necessary for their specific job function, reducing the attack surface and risk of misuse.
What is a 'super user' in an ERP security context?
Answer: An account with unrestricted access to all system functions and data
Super users have unrestricted system access and are typically reserved for emergency situations or system administrators with special oversight requirements.
Which control best prevents a single user from both creating a vendor record and processing payment to that vendor?
Answer: Segregation of Duties (SoD) controls
SoD controls separate conflicting duties (creating vendors vs. processing payments) to prevent fraud where one person could create fictitious vendors and pay them.
In an ERP system, what is an 'authorization object'?
Answer: A data structure defining what actions users can perform on specific data
Authorization objects in ERP systems define combinations of fields and values that control what actions a user can take on specific data objects.
Which user account type should be used for day-to-day business operations in an ERP system?
Answer: Standard user account with role-appropriate permissions
Standard user accounts with limited, role-appropriate permissions should be used for daily operations to minimize security risk and comply with least privilege.