ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationHard

An IS auditor is assessing the controls over system maintenance for a critical production database. The organization uses a 'break-fix' model where database administrators (DBAs) directly modify the production database to resolve urgent issues. Which of the following controls would BEST mitigate the risk of unauthorized or erroneous changes in this scenario?

  1. AComprehensive logging of all database changes and administrator actions.
  2. BRegular reconciliation of production database schema with a baseline.
  3. CDaily backups of the production database.
  4. DMandatory peer review of all SQL scripts before execution.
Show answer & explanation

Correct answer: A. Comprehensive logging of all database changes and administrator actions.

While 'break-fix' direct modifications are high-risk, comprehensive logging of all database changes and administrator actions (including who, what, when, and where) provides an audit trail. This acts as a strong detective and deterrent control, allowing for immediate identification of unauthorized or erroneous changes, facilitating recovery, and holding individuals accountable, thereby best mitigating the risk in a scenario where preventative controls (like testing) are bypassed.

Why the other options are wrong

  • B. Regular reconciliation helps detect deviations but is not real-time and doesn't capture *who* made a change or *when*, making it less effective for immediate risk mitigation than comprehensive logging.
  • C. Daily backups are crucial for recovery, but they are a reactive control and do not prevent or immediately detect unauthorized/erroneous changes.
  • D. Peer review is a good preventative control, but in an urgent 'break-fix' scenario, scripts might still be executed without it, or errors might be missed. Logging is a more robust detective control for *all* actions.

Database Change Controls

Measures implemented to ensure that modifications to database schemas, data, or configuration are authorized, tested, and tracked to maintain integrity and availability.

  • Includes change management, version control, and logging.
  • Critical for data integrity and system stability.
  • Direct production changes are high-risk.
  • Strong detective controls are essential for 'break-fix' models.

Memory trick: Break-Fix: Log Everything, Catch Anything.

More Domain 3: Information Systems Acquisition, Development and Implementation questions