ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITHard

A CISA is auditing an organization's IT organizational structure. The CISA observes that the Head of Development also serves as the Head of Quality Assurance (QA) for all new software releases. Which of the following is the MOST significant risk introduced by this structure?

  1. AReduced innovation in software development processes.
  2. BHigher operational costs due to redundant staffing.
  3. CCompromised objectivity and effectiveness of quality control.
  4. DIncreased project timelines due to conflicting priorities.
Show answer & explanation

Correct answer: C. Compromised objectivity and effectiveness of quality control.

This scenario represents a classic violation of segregation of duties (SoD). When the same individual is responsible for both developing software and assuring its quality, there is an inherent conflict of interest. The Head of Development might be incentivized to overlook defects or rush testing to meet development deadlines, thereby compromising the objectivity and effectiveness of the quality assurance function. This significantly increases the risk of deploying faulty or insecure software.

Why the other options are wrong

  • A. Innovation is not directly affected by this SoD violation; rather, quality and security are.
  • B. This structure might actually reduce staffing, but at the cost of control effectiveness, which is a greater risk.
  • D. While possible, the most significant risk is the integrity of the software itself, not just project timelines.

Segregation of Duties (SoD)

A control principle that divides critical functions or tasks among multiple individuals to prevent a single person from having excessive control that could lead to errors, fraud, or unauthorized actions.

  • Reduces the risk of fraud and error.
  • Requires independent checks and balances.
  • Essential in IT for roles like development, operations, and security.

Memory trick: SoD: Separate Hands, Secure Plans.

More Domain 2: Governance and Management of IT questions