ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationEasy

An IS auditor is reviewing the change management process for a critical production system. A recent emergency patch was implemented without following the standard testing and approval procedures due to an urgent security vulnerability. What is the MOST critical control to ensure the integrity of the system after such an emergency change?

  1. AImmediate update of change documentation to reflect the emergency patch.
  2. BPost-implementation review and full testing of the emergency change.
  3. CApproval by senior management for bypassing standard procedures.
  4. DCommunication to all affected stakeholders about the change.
Show answer & explanation

Correct answer: B. Post-implementation review and full testing of the emergency change.

While emergency changes necessitate bypassing some controls, a thorough post-implementation review and full testing are crucial to validate the change, ensure it resolved the issue without introducing new problems, and verify system integrity.

Why the other options are wrong

  • A. Documentation is important for audit trails, but it does not verify the integrity or functionality of the change itself.
  • C. Senior management approval provides governance oversight but does not technically validate the change or its impact on the system.
  • D. Communication is important for operational awareness but does not ensure the technical integrity of the system.

Emergency Change Post-Review

A critical step after an emergency change to validate its effectiveness, assess its impact, and ensure system integrity and stability.

  • Compensates for bypassed standard controls.
  • Includes full testing and impact analysis.
  • Ensures the system returns to a controlled state.

Memory trick: After the emergency, review to ensure no new urgency.

More Domain 3: Information Systems Acquisition, Development and Implementation questions