ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationHard
An IS auditor is evaluating controls over system maintenance for a critical production database. The organization uses a change management system that logs all changes. However, the auditor discovers that database administrators (DBAs) can make direct changes to the production database without formal approval or prior testing if they deem it an emergency. What is the MOST significant risk this practice introduces?
- APotential for performance degradation due to unoptimized queries.
- BExcessive reliance on DBA expertise for critical system stability.
- CIncreased downtime due to uncoordinated changes.
- DDifficulty in tracking and auditing unauthorized changes.
Show answer & explanationAnswer & explanation
Correct answer: D. Difficulty in tracking and auditing unauthorized changes.
Bypassing formal approval and testing for emergency changes, even if well-intentioned, creates a significant control weakness. The MOST significant risk is the inability to track and audit these changes, which can lead to data integrity issues, security vulnerabilities, and difficulty in root cause analysis.
Why the other options are wrong
- A. Performance degradation is a possible outcome of unoptimized changes, but the core control failure is the lack of oversight and traceability for such changes.
- B. While reliance on expertise is a risk, the more direct and significant risk here is the lack of controlled process and auditability of changes.
- C. Increased downtime is a potential consequence, but the root cause of the risk is the lack of control and auditability over the change itself.
Database Direct Change Risk
The risk that direct, unapproved, and untested changes to a production database can compromise data integrity, security, and auditability.
- Bypasses formal change management controls.
- Creates audit trail gaps.
- Increases risk of errors, data corruption, and unauthorized access.
Memory trick: Direct database changes without paperwork make for audit nightmares.