ExamGecko
Question list
Search
Search

Related questions











Question 739 - CISA discussion

Report
Export

An IS auditor noted a recent production incident in which a teller transaction system incorrectly charged fees to customers due to a defect from a recent release. Which of the following should be the auditor's NEXT step?

A.
Evaluate developer training.
Answers
A.
Evaluate developer training.
B.
Evaluate the incident management process.
Answers
B.
Evaluate the incident management process.
C.
Evaluate the change management process.
Answers
C.
Evaluate the change management process.
D.
Evaluate secure code practices.
Answers
D.
Evaluate secure code practices.
Suggested answer: C

Explanation:

The change management process is the set of procedures and activities that ensure that changes to the information system are authorized, tested, documented, and implemented in a controlled manner12.A defect in a recent release indicates that there may be issues with the quality assurance, testing, or approval of the changes, which could affect the reliability, security, and performance of the system3. Therefore, the auditor's next step should be to evaluate the change management process and identify the root cause of the defect, as well as the impact and remediation of the incident.

Reference

1: Change Management - CISA

2: What is Change Management?- Definition from Techopedia

3: How to Audit Change Management - ISACA Journal

: The Business Case for Security | CISA

asked 18/09/2024
Carola Lotito
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first