한 소규모 조직이 IT 인력을 감축하고 핵심 업무를 최고참 IT 엔지니어 한 명에게 통합하여 비용을 절감했습니다. 이러한 상황에서 가장 중요한 위험은 무엇일까요?
정답: C
The correct answer is C. The consolidated responsibilities do not allow for appropriate separation of duties.
The primary risk is that too many critical responsibilities are concentrated in one individual. This creates a segregation/separation of duties issue, because one person may be able to initiate, approve, implement, and monitor critical IT activities without independent review. In IT, this could allow unauthorized changes, inappropriate access, fraud, errors, or malicious actions to occur without timely detection.
ISACA defines segregation/separation of duties as a basic internal control that prevents or detects errors and irregularities by assigning incompatible responsibilities to different individuals. ISACA also notes that SoD helps ensure no single person is in a position to introduce fraudulent or malicious code without detection.
Option A is not the best answer because resource optimization may be affected, but the major control risk is excessive authority and incompatible duties. Option B is incorrect because the issue is not limited authority; the concern is too much combined authority. Option D is a valid secondary concern because succession planning may be weakened when knowledge is concentrated in one person, but CISA questions usually prioritize the control risk of inadequate separation of duties over staffing continuity concerns.
This maps mainly to Governance and Management of IT because the issue relates to organizational structure, IT governance, resource management, roles, responsibilities, and control ownership. ISACA's CISA Exam Content Outline includes organizational structure, IT governance, IT resource management, and determining whether ownership of IT risk, controls, and standards has been defined.
References: ISACA CISA Exam Content Outline, Domain 2; ISACA Interactive Glossary, "Segregation
/separation of duties."