ExamGecko
Question list
Search
Search

Related questions











Question 270 - CISA discussion

Report
Export

Providing security certification for a new system should include which of the following prior to the system's implementation?

A.
End-user authorization to use the system in production
Answers
A.
End-user authorization to use the system in production
B.
External audit sign-off on financial controls
Answers
B.
External audit sign-off on financial controls
C.
Testing of the system within the production environment
Answers
C.
Testing of the system within the production environment
D.
An evaluation of the configuration management practices
Answers
D.
An evaluation of the configuration management practices
Suggested answer: D

Explanation:

Providing security certification for a new system should include an evaluation of the configuration management practices prior to the system's implementation. Configuration management is a process that ensures that the system's components are identified, controlled, and tracked throughout the system's lifecycle. Configuration management helps to maintain the security and integrity of the system by preventing unauthorized or unintended changes. End-user authorization to use the system in production is not part of security certification, but rather a post-implementation activity that grants access rights to authorized users. External audit sign-off on financial controls is not part of security certification, but rather a verification activity that ensures that the system complies with financial reporting standards. Testing of the system within the production environment is not part of security certification, but rather a validation activity that ensures that the system meets the functional and performance requirements.Reference:

CISA Review Manual, 27th Edition, pages 449-4501

CISA Review Questions, Answers & Explanations Database, Question ID: 2572

asked 18/09/2024
ALLIE SEBRONE MUHAMUBI
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first