Procedure Step:Separation of Duties
Audit Step:
Obtain an organization chart and discuss job classifications and duties with appropriate employees. Assess whether adequate separation of duties exists over the application (Consider FISCAM as a guide. Considering completing the "Separation of Duties checklist to help in assessing controls).
Purpose:
To obtain an understanding of the application’s security environment.

