In a purchasing department, which pairing of duties is the separation-of-duty conflict that an RBAC design must forbid?
In a purchasing department, which pairing of duties is the separation-of-duty conflict that an RBAC design must forbid?
Answer
Recording that goods were received and approving payment for them
Options - A. Recording that goods were received and approving payment for them - B. Reading part descriptions and reading stock levels - C. Amending a vendor address and reading a purchase order - D. Creating a purchase order and reading part descriptions Why - A. Correct — one person holding both could record a fictitious delivery from a vendor they control and then settle the invoice for it. Splitting them means fraud requires collusion. - B. Two read rights over reference data. Neither one authorises a transaction, so combining them creates no abusable pair. - C. A plausible-looking pair, but reading an order is passive. The dangerous combination is amending the payee AND approving the payment, not amending and reading. - D. Ordering and looking up what you are ordering are the same job function. Separating them would be granularity for its own sake. The test for a separation-of-duty conflict: could one person start a transaction and also complete or approve it, with no second party in the loop? If yes, the two duties belong to different, mutually exclusive roles.
Stallings & Brown, Computer Security 5e, ch4 §4.7–§4.10