ExamGecko
Question list
Search
Search

Related questions

Question 11 - CISA discussion

Report
Export

Controls related to authorized modifications to production programs are BEST tested by:

A.
tracing modifications from the original request for change forward to the executable program.
Answers
A.
tracing modifications from the original request for change forward to the executable program.
B.
tracing modifications from the executable program back to the original request for change.
Answers
B.
tracing modifications from the executable program back to the original request for change.
C.
testing only the authorizations to implement the new program.
Answers
C.
testing only the authorizations to implement the new program.
D.
reviewing only the actual lines of source code changed in the program.
Answers
D.
reviewing only the actual lines of source code changed in the program.
Suggested answer: A

Explanation:

Controls related to authorized modifications to production programs are best tested by tracing modifications from the original request for change forward to the executable program, as this ensures that the change management process was followed and that the modifications were approved, documented, tested, and implemented correctly. Tracing modifications from the executable program back to the original request for change may not reveal any unauthorized or undocumented changes that occurred during the process. Testing only the authorizations to implement the new program or reviewing only the actual lines of source code changed in the program are not sufficient to test the controls related to authorized modifications, as they do not cover the entire change management process.Reference:CISA Review Manual (Digital Version), Chapter 4: Information Systems Operations, Maintenance and Service Management, Section 4.2: Change Management

asked 18/09/2024
Shane Behrendt
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first