I am struggling with an IT concept that I came across in the Becker book (B4-33).
The book specifically says that systems analysts and computer programmers should have segregation of duties.
Then I got a MCQ that reads as follows:
Which of the following statements is not correct for segregation of duties in an IT environment?
a. The IT department is a support group in that it normally does not initiate or authorize transactions.
b. Segregation of duties in an IT environment normally revolves around granting and/or restricting access to production data and/or production programs.
c. The duties of system analysts and application programmers should never be combined.
d. Segregation of duties in an IT environment is defined as dividing responsibilities for different portions of a transaction among several different people.
Here's the answer:
Choice “c” is correct as it is the only incorrect statement. The duties of system analysts and application programmers can be, and often are, combined. The duties of system programmers and application programmers should not be combined.
These two points seem to contradict each other. Anyone else struggling with this?