CRISC Certified in Risk and Information Systems Control – Question368

Which of the following test is BEST to map for confirming the effectiveness of the system access management process?

A.
user accounts to human resources (HR) records.
B. user accounts to access requests.
C. the vendor database to user accounts.
D. access requests to user accounts.

Correct Answer: B

Explanation:

Explanation: Tying user accounts to access requests confirms that all existing accounts have been approved. Hence, the effectiveness of the system access management process can be accounted.
Incorrect Answers:
A: Tying user accounts to human resources (HR) records confirms whether user accounts are uniquely tied to employees, not accounts for the effectiveness of the system access management process.
C: Tying vendor records to user accounts may confirm valid accounts on an e-commerce application, but it does not consider user accounts that have been established without the supporting access request.
D: Tying access requests to user accounts confirms that all access requests have been processed; however, the test does not consider user accounts that have been established without the supporting access request.