ExamGecko
Question list
Search
Search

Related questions

Question 975 - CISA discussion

Report
Export

Which of the following would provide the BEST evidence that a cloud provider's change management process is effective?

A.
Minutes from regular change management meetings with the vendor
Answers
A.
Minutes from regular change management meetings with the vendor
B.
Written assurances from the vendor's CEO and CIO
Answers
B.
Written assurances from the vendor's CEO and CIO
C.
The results of a third-party review provided by the vendor
Answers
C.
The results of a third-party review provided by the vendor
D.
A copy of change management policies provided by the vendor
Answers
D.
A copy of change management policies provided by the vendor
Suggested answer: C

Explanation:

The results of a third-party review provided by the vendor would provide the best evidence that a cloud provider's change management process is effective, because it would be an independent and objective assessment of the vendor's compliance with best practices and standards for managing changes in the cloud environment. A third-party review would also include testing of the vendor's change management controls and procedures, and provide recommendations for improvement if needed.

Minutes from regular change management meetings with the vendor would not provide sufficient evidence, because they would only reflect the vendor's self-reported information and may not capture all the changes that occurred or their impact on the cloud services. Written assurances from the vendor's CEO and CIO would also not provide sufficient evidence, because they would be based on the vendor's own opinion and may not be verified by external sources. A copy of change management policies provided by the vendor would not provide sufficient evidence, because it would only show the vendor's intended approach to change management, but not how it is implemented or monitored in practice.

ISACA Cloud Computing Audit Program, Section 4.5: Change Management

Cloud Computing: Business Benefits With Security, Governance and Assurance Perspectives, Section 4.3: Change Management

asked 18/09/2024
rashid Elamin
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first