The security team plans on using automated account reconciliation in the corporate user access review process.
Which of the following must be implemented for the BEST results with fewest errors when running the audit?
Correct Answer: C
Clear provisioning policies are essential for the best results with fewest errors when running the audit using automated account reconciliation. Automated account reconciliation is a process that compares the user accounts and access rights in the system with the expected or authorized accounts and access rights, and identifies any discrepancies or anomalies. Clear provisioning policies define the rules and criteria for creating, modifying, deleting, and reviewing user accounts and access rights, and they provide a baseline for the automated account reconciliation process. The other options are not correct. Removal of service accounts from review may reduce the scope of the audit, but it may also introduce errors or risks if the service accounts are not properly managed or secured. Segregation of Duties (SoD) is a principle that prevents a single user from having conflicting or excessive access rights, but it does not ensure the accuracy or completeness of the automated account reconciliation process. Frequent audits may increase the frequency of the automated account reconciliation process, but they do not improve the quality or reliability of the process.
References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 8: Security Operations, page 1039. Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 7: Security Operations, page 1040.