Testing the Independence of Control Performers and License Exposure

Sdílet
Vložit
  • čas přidán 5. 09. 2024
  • How to test the independence of control performers and identify license exposure
    Testing the independence of control performers
    The person performing each control must have independence from the activities they are monitoring. However, organizations do not always have certainty as to whether this is the case or not. To confirm this independence, the auditor should understand how the control is performed and should understand the data related to the control. This requires the auditor to confirm the control performer does not have access to maintain the data they are overseeing in the control design.
    License Exposure
    Most ERP software providers clearly identify what abilities are tied to licenses. In these cases, access control software can be used to identify what is the current license usage. Access control software is particularly useful given it de-normalizes the roles assigned to users to provide a clear understanding of what roles and security objects a user has access to. This ‘denormalized’ data is also the same data needed to understand what security objects a user has that drive the demand for a software license.

Komentáře •