ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationMedium

An IS auditor is reviewing the controls over software maintenance for an internally developed application. User feedback indicates that system performance has degraded significantly after recent production updates. Which of the following controls is MOST likely to have failed?

  1. AFormal change request and approval process.
  2. BVersion control for software code and configurations.
  3. CSegregation of duties between development and production environments.
  4. DAdequate testing of changes before deployment.
Show answer & explanation

Correct answer: D. Adequate testing of changes before deployment.

Significant performance degradation after production updates strongly suggests that the changes were not adequately tested for their impact on system performance, stability, or resource utilization before being deployed to the live environment.

Why the other options are wrong

  • A. A formal change process ensures authorization but doesn't guarantee the technical quality of the change or its testing.
  • B. Version control manages code versions but doesn't inherently prevent performance issues if the code itself is flawed or untested.
  • C. SoD prevents unauthorized changes but doesn't guarantee the quality of authorized changes.

Software Change Testing

The process of verifying that modifications to software function as intended, do not introduce new defects, and do not negatively impact existing functionality or performance before deployment.

  • Prevents regressions and new defects.
  • Ensures system stability and performance.
  • Reduces risk of production incidents.

Memory trick: Updated code, but did you 'TEST' it right?

More Domain 3: Information Systems Acquisition, Development and Implementation questions