ExamGecko
Question list
Search
Search

Related questions

Question 1105 - CISA discussion

Report
Export

Which of the following is the BEST compensating control against segregation of duties conflicts in new code development?

A.
Adding the developers to the change approval board
Answers
A.
Adding the developers to the change approval board
B.
A small number of people have access to deploy code
Answers
B.
A small number of people have access to deploy code
C.
Post-implementation change review
Answers
C.
Post-implementation change review
D.
Creation of staging environments
Answers
D.
Creation of staging environments
Suggested answer: C

Explanation:

A post-implementation change review is the best compensating control against segregation of duties conflicts in new code development.This process involves a thorough review of the changes after they have been implemented to ensure that they meet their objectives and that the stakeholders are satisfied with the results1. It provides an opportunity to identify and correct any issues or conflicts that may have arisen during the development and implementation process.While other options like adding developers to the change approval board, limiting code deployment access to a small number of people, and creating staging environments can also serve as compensating controls, a post-implementation change review provides a more comprehensive and effective control mechanism21.

Review and Close Change process ST 2 5 - Micro Focus

Change Management for SOC: Risks, Controls, Audits, Guidance

asked 18/09/2024
Abigail Bormann
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first