ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationEasy
An IS auditor is evaluating the controls over a new financial reporting system still in the development phase. Which of the following would be the MOST effective control to ensure that only authorized and tested code changes are promoted to the production environment?
- AAutomated regression testing after every code commit.
- BSegregation of duties between development, testing, and production environments.
- CDaily code reviews by peer developers.
- DMandatory use of a version control system.
Show answer & explanationAnswer & explanation
Correct answer: B. Segregation of duties between development, testing, and production environments.
Segregation of duties (SoD) between development, testing, and production environments is a fundamental control that prevents unauthorized or untested code from being promoted to production. It ensures that no single individual or team has control over all stages of the software development lifecycle, thereby reducing the risk of fraud or errors.
Why the other options are wrong
- A. Automated regression testing verifies functionality but doesn't control *who* promotes code or *what* code is promoted.
- C. Daily code reviews are good for quality but don't inherently prevent unauthorized promotion to production.
- D. A version control system tracks changes but doesn't enforce the separation of roles required to prevent unauthorized production deployment.
Segregation of Duties (SoD)
A control principle that divides critical functions among different individuals or teams to prevent any single person from having complete control over a process, thereby reducing the risk of error, fraud, or misuse.
- Prevents a single point of failure or compromise.
- Enhances internal control effectiveness.
- Commonly applied in financial, IT, and operational processes.
Memory trick: SoD: Separate Duties, Secure Deployment.