Proper Authorization for User Accounts | CRISC Exam | ISACA

Best Evidence of Properly Authorized User Accounts

Prev Question Next Question

Question

Which of the following is the BEST evidence that a user account has been properly authorized?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

C.

The BEST evidence that a user account has been properly authorized is option B, formal approval of the account by the user's manager.

Option A, notification from human resources that the account is active, is not sufficient evidence that the account was properly authorized. HR may not have the necessary information or authority to properly authorize the account.

Option C, user privileges matching the request form, is also not sufficient evidence that the account was properly authorized. User privileges can be adjusted after the account has been created, and therefore may not accurately reflect the initial authorization process.

Option D, an email from the user accepting the account, is also not sufficient evidence of proper authorization. The user may have accepted the account without proper authorization or without fully understanding the authorization process.

Formal approval by the user's manager provides the necessary level of authorization required to ensure that the account was properly authorized. The manager is typically responsible for authorizing access to information and resources within an organization, and therefore is the appropriate authority to approve a user account.