ExamGecko
Question list
Search
Search

Related questions











Question 604 - CISA discussion

Report
Export

Which of the following should be of GREATEST concern to an IS auditor who is assessing an organization's configuration and release management process?

A.
The organization does not use an industry-recognized methodology
Answers
A.
The organization does not use an industry-recognized methodology
B.
Changes and change approvals are not documented
Answers
B.
Changes and change approvals are not documented
C.
All changes require middle and senior management approval
Answers
C.
All changes require middle and senior management approval
D.
There is no centralized configuration management database (CMDB)
Answers
D.
There is no centralized configuration management database (CMDB)
Suggested answer: B

Explanation:

The greatest concern to an IS auditor who is assessing an organization's configuration and release management process is that changes and change approvals are not documented. This is because documentation is essential for ensuring the traceability, accountability, and quality of the changes made to the configuration items (CIs) and the releases deployed to the production environment. Without documentation, it would be difficult to verify the authenticity, validity, and authorization of the changes, as well as to identify and resolve any issues or incidents that may arise from the changes. Documentation also helps to maintain compliance with internal and external standards and regulations, as well as to facilitate audits and reviews.

The other options are not as concerning as option B, although they may also indicate some weaknesses in the configuration and release management process. The organization does not use an industry-recognized methodology, but this does not necessarily mean that their process is ineffective or inefficient. The organization may have developed their own methodology that suits their specific needs and context. However, using an industry-recognized methodology could help them adopt best practices and improve their process maturity. All changes require middle and senior management approval, but this may not be a problem if the organization has a clear and streamlined approval process that does not cause delays or bottlenecks in the change implementation. However, requiring too many approvals could also introduce unnecessary complexity and bureaucracy in the process. There is no centralized configuration management database (CMDB), but this does not mean that the organization does not have a way of managing their CIs and their relationships. The organization may use other tools or methods to store and access their configuration data, such as spreadsheets, documents, or repositories. However, having a centralized CMDB could help them improve their visibility, accuracy, and consistency of their configuration data.

1: The Essential Guide to Release Management | Smartsheet

2: 5 steps to a successful release management process - Lucidchart

3: Configuration Management process overview - Micro Focus

4: Release and Deployment Management process overview - Micro Focus

asked 18/09/2024
Saran Lertrat
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first