Payroll specialists click a fake open-enrollment link that spoofs the city's benefits portal. The CHRO is aligning HR processes to the municipal cyber strategy. Which control should HR and IT apply?
Select an answer to reveal the explanation.
Short Explanation
Payroll keys are not the same as a library-front-desk login. A poster for everybody is like putting the same lock on the vault and the break-room fridge. High-privilege HR seats need extra checks—MFA and a second channel—before money or benefits move.
Full Explanation
Roles that can alter pay, tax, and benefits data are high-value phishing targets, so the cyber strategy should apply tighter controls than generic awareness. Multi-factor authentication and out-of-band verification for sensitive HR transactions reduce the chance that a spoofed enrollment link becomes a successful change. Citywide posters, a return to paper payroll, or banning email do not target the actual privilege risk. HR and IT should design role-based controls around those HR processes.