ExamGecko
Question list
Search
Search

Related questions











Question 588 - CISA discussion

Report
Export

An IS auditor discovers that due to resource constraints a database administrator (DBA) is responsible for developing and executing changes into the production environment Which ot the following should the auditor do FIRSTS

A.
Determine whether another DBA could make the changes
Answers
A.
Determine whether another DBA could make the changes
B.
Report a potential segregation of duties violation
Answers
B.
Report a potential segregation of duties violation
C.
identify whether any compensating controls exist
Answers
C.
identify whether any compensating controls exist
D.
Ensure a change management process is followed prior to implementation
Answers
D.
Ensure a change management process is followed prior to implementation
Suggested answer: C

Explanation:

A database administrator (DBA) is responsible for maintaining the integrity, security and performance of the database systems. A DBA who is also responsible for developing and executing changes into the production environment may have a conflict of interest and pose a risk to the data quality and availability. Therefore, the IS auditor should first identify whether any compensating controls exist to mitigate this risk, such as independent reviews, approvals, audits or monitoring of the changes. Determining whether another DBA could make the changes, reporting a potential segregation of duties violation and ensuring a change management process is followed prior to implementation are possible actions that the auditor could take after identifying the compensating controls or the lack thereof.Reference:

:Database Administrator (DBA) Definition

:Segregation of Duties | ISACA

: [Compensating Control Definition]

asked 18/09/2024
Oleksandr Kondratchuk
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first