プログラマーが給与システム レポートの主要フィールドに不正な変更を加えました。この問題の原因として最も大きな影響を与えたと考えられるのは次のどの管理上の弱点でしょうか。
正解:D
The programmer having access to the production programs is the most likely control weakness that would have contributed to the unauthorized changes to the payroll system report. This is because the programmer could modify the production code without proper authorization, documentation, or testing, and bypass the change management process. This could result in errors, fraud, or data integrity issues in the payroll system.
The programmer should only have access to the development or test environment, and the production programs should be under the control of a librarian or a change manager.
References
ISACA CISA Review Manual, 27th Edition, page 254
4 Types of Internal Control Weaknesses
ACCT 4631 - Internal Auditing: CIA Quiz Topic 6 Flashcards