Webos's project failed due to the lack of segregation of duties. Which threat can impact Webos in this situation?

Prepare for the ISO/IEC 27001 Lead Auditor Exam with comprehensive flashcards and multiple-choice questions. Gain confidence with detailed explanations and hints. Succeed in your certification endeavor!

The choice of unauthorized use of the system highlights a significant risk associated with the lack of segregation of duties in an organization. Segregation of duties (SoD) is a crucial internal control mechanism that helps ensure that no single individual has control over all aspects of any critical process, which can prevent fraud or errors. When duties are not properly segregated, it increases the risk that one individual can manipulate the system without checks and balances, leading to unauthorized access and actions.

In the context of Webos, the absence of this control may allow individuals to conduct malicious activities, such as data theft or unauthorized data manipulation, without being detected. This can result in severe consequences, including data breaches, reputational damage, and financial loss. Therefore, the identification of unauthorized use of the system as a threat is rooted in the clear relationship between SoD and the safeguarding of information integrity, availability, and confidentiality.

In contrast, the other options focus on operational issues or consequences that may arise from risks but do not directly capture the immediate threat associated with the violation of segregation of duties. Failure to produce management reports, insufficient software testing, and inaccurate documentation while important issues to address, do not directly relate to the unauthorized access risks that stem from inadequate SoD controls.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy