Question 1 Report
A company wants to protect its network using different levels of access control.
| User role | Access level | Justification |
|---|---|---|
| Receptionist | Can view customer contact details only | |
| Sales manager | Can view and edit customer orders and contact details | |
| IT administrator | Full access to all systems and data | |
| Temporary intern | Read-only access to training materials |
(a) Complete the table by giving a justification for each user role's access level. [4]
(b) Explain two risks that could arise if all employees were given full access to all data. [4]
(a) Justification for each user role's access level [4]
| User Role | Access Level | Justification |
|---|---|---|
| Receptionist | Can view customer contact details only | The receptionist only needs contact details to direct enquiries and schedule appointments. They do not need access to financial records, order data, or other sensitive business information. [1] |
| Sales manager | Can view and edit customer orders and contact details | The sales manager needs to view customer records to manage client accounts and must be able to edit orders to process new sales, handle returns, and respond to customer queries. [1] |
| IT administrator | Full access to all systems and data | The IT administrator requires full access to configure systems, install and update software, create and manage user accounts, and troubleshoot problems across the entire network infrastructure. [1] |
| Temporary intern | Read-only access to training materials | The intern is only in the company for a short period and should have minimal access to reduce the risk of accidental data changes or security breaches. Read-only training materials are sufficient for their learning role. [1] |
(b) Two risks if all employees were given full access [4]
Everything you need to excel in your exams