ExamGecko
Question list
Search
Search

Related questions

Question 1016 - CISA discussion

Report
Export

Which of the following observations should be of GREATEST concern to an IS auditor performing an audit of change and release management controls for a new complex system developed by a small in-house IT team?

A.
Access to change testing strategy and results is not restricted to staff outside the IT team.
Answers
A.
Access to change testing strategy and results is not restricted to staff outside the IT team.
B.
Some user acceptance testing (IJAT) was completed by members of the IT team.
Answers
B.
Some user acceptance testing (IJAT) was completed by members of the IT team.
C.
IT administrators have access to the production and development environment
Answers
C.
IT administrators have access to the production and development environment
D.
Post-implementation testing is not conducted for all system releases.
Answers
D.
Post-implementation testing is not conducted for all system releases.
Suggested answer: D

Explanation:

Post-implementation testing is the process of verifying and validating the functionality, performance, and security of a system after it has been deployed to the production environment1. Post-implementation testing is important for ensuring that the system meets the user requirements and expectations, as well as the operational and business objectives.Post-implementation testing also helps to identify and resolve any defects, errors, or issues that may have occurred during the deployment process or that may have been missed during the previous testing stages2.

Therefore, the observation that post-implementation testing is not conducted for all system releases should be of greatest concern to an IS auditor performing an audit of change and release management controls for a new complex system developed by a small in-house IT team. This observation indicates that the system may have quality, reliability, or security problems that could affect the user satisfaction, system performance, or data integrity. This observation also suggests that the change and release management controls are not adequate or effective, as they do not ensure that all system releases are properly tested and validated before and after deployment.

Option A is not correct because access to change testing strategy and results is not restricted to staff outside the IT team is not a major concern for an IS auditor. While it is good practice to limit access to sensitive or confidential information, such as test data or test cases, to authorized personnel only, access to change testing strategy and results may not pose a significant risk to the system or the organization. Moreover, access to change testing strategy and results may be beneficial for some stakeholders outside the IT team, such as business users, project managers, or auditors, who may need to review or evaluate the testing process or outcomes.

Option B is not correct because some user acceptance testing (UAT) was completed by members of the IT team is not a major concern for an IS auditor.User acceptance testing is the process of verifying and validating that the system meets the user requirements and expectations by involving actual or representative users in the testing process3. While it is preferable to have independent and unbiased users perform UAT, it may not be feasible or practical for some organizations, especially those with small or limited resources. Therefore, some UAT may be completed by members of the IT team, as long as they have sufficient knowledge and experience of the user needs and expectations, and as long as they follow the UAT plan and criteria.

Option C is not correct because IT administrators have access to the production and development environment is not a major concern for an IS auditor.IT administrators are responsible for managing and maintaining the IT infrastructure, including the production and development environments4. Therefore, it is reasonable and necessary for them to have access to both environments, as long as they follow the appropriate policies and procedures for accessing, using, and securing them. Moreover, IT administrators may need to perform tasks such as backup, restore, patching, or troubleshooting in both environments.

What Is Post Implementation Testing?1

Post Implementation Review (PIR) - Definition & Process2

User Acceptance Testing (UAT): Definition & Examples3

What Is an IT Administrator?Definition & Examples4

asked 18/09/2024
Do Hien
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first