CPA Information Systems and Controls (ISC) Question of the Day

Test your knowledge with a hand-picked multiple-choice question.

Database administrators share a generic 'dbadmin' account to perform production changes, and the password is stored in a team wiki and rotated quarterly. Auditors noted several schema changes that cannot be tied to an individual, and a privileged access management tool was purchased but only used for password vaulting. Session recording and approvals for elevation are not enabled, and named accounts exist but are not used for administrative tasks. Management asks which general control is missing to strengthen accountability and oversight of privileged activities.

Which control is missing?

Select an answer and click Check.