Question #1
An internal auditor needs to test logical controls to determine whether all users access the organization's enterprise resource planning system according to the principle of least privilege.Which engagement procedure would be most effective in carrying out this test?
- A.
Obtain the user access list created by management that shows user roles and permissions, and observe the actions of a sample of users for consistency.
- B.
Generate a user access list from the system that shows roles and permissions, and observe the actions of a sample of users for consistency.
- C.
Generate a user access list from the system that shows roles and permissions, and use access rights management software to confirm permissions.
- D.
Obtain the user access list created by management that shows user roles and permissions, and compare with job descriptions for consistency.
Answer: C
The core audit objective here is to test logical controls to verify all ERP system users adhere to the principle of least privilege, meaning no user has more access than required to perform their authorized job functions. For this test, two critical elements are required to ensure audit evidence is reliable and the test is comprehensive: first, the auditor must use the actual, active access permissions configured in the ERP system rather than potentially inaccurate management-prepared documentation, and second, the test must cover all permissions assigned to users, not just a limited subset of observed activity. Option C meets both requirements: pulling the access list directly from the system eliminates the risk of relying on outdated or incorrect management-provided lists, and using access rights management software enables systematic, automated validation of all assigned permissions against least privilege requirements, including identifying overprovisioned access, orphaned accounts, and excessive rights that would not be detected via limited sampling or manual comparison. This aligns with CIA Part 2 2025 guidance on testing IT logical controls, which prioritizes direct system evidence and automated testing tools for more accurate, complete control assessment. Option Analysis:
A. Incorrect. First, the management-created user access list is not validated against actual system configurations, so it may contain errors, outdated entries, or omissions that do not reflect true access rights. Second, observing a sample of user actions only captures activities performed during the observation window, and cannot detect excess permissions that the user holds but does not use during observation, so it fails to comprehensively test least privilege for all assigned access.
B. Incorrect. While generating the access list directly from the system provides reliable baseline data on actual configured permissions, observing a sample of user actions is still insufficient. Observation only captures a narrow, time-bound subset of user activity, and cannot identify overprovisioned access that is not exercised during the observation period, so it does not fully validate that all assigned permissions align with least privilege.
C. Correct. This procedure addresses both key requirements for the test: system-generated access lists provide reliable, accurate data on the actual active permissions in the ERP, eliminating reliance on potentially flawed management documentation. Access rights management software is purpose-built to systematically map assigned permissions to required job functions, identify excessive or unused rights, and validate alignment with least privilege across all users, delivering a far more complete and accurate assessment than manual or sample-based procedures. This directly meets the audit objective and adheres to CIA Part 2 best practices for logical access control testing.
D. Incorrect. First, the management-created access list is not verified against actual system configurations, so it may not reflect true access rights. Second, comparing access lists to job descriptions is a high-level, imprecise check, as job descriptions rarely include granular details of required ERP system permissions, so it cannot reliably identify excess granular access that violates least privilege. Key Concepts:
1. Reliability of Audit Evidence: CIA Part 2 guidance establishes that evidence obtained directly by the auditor from the underlying system (e.g., system-generated access lists) is far more reliable than evidence provided by management, as it reduces the risk of manipulation or inaccuracy in management-prepared documentation.
2. Logical Access Control Testing for Least Privilege: Testing least privilege requires validating that all assigned access permissions, not just actively used permissions, are limited to the minimum required for a user's job function, as unexercised excess permissions present a material control risk.
3. Automated Control Testing Efficiency and Completeness: CIA Part 2 recommends using automated tools (such as access rights management software) for testing IT controls where possible, as these tools can evaluate entire populations of access rights rather than limited samples, reducing sampling risk and improving the accuracy of test results. References:
The IIA International Standards for the Professional Practice of Internal Auditing, Standard 2310: Identifying Information, The IIA Global Technology Audit Guide (GTAG) 1: Information Technology Controls