ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationMedium

An IS auditor is reviewing an organization's change management process for critical production systems. The auditor notes that emergency changes, while documented post-implementation, often bypass standard testing and approval procedures. What is the MOST critical risk introduced by this practice?

  1. AIncreased unauthorized access attempts by external parties.
  2. BDifficulty in proving regulatory compliance for system changes.
  3. CHigher likelihood of system instability and service outages.
  4. DInefficient resource allocation for development teams.
Show answer & explanation

Correct answer: C. Higher likelihood of system instability and service outages.

Bypassing standard testing and approval for emergency changes significantly increases the risk of introducing errors, incompatibilities, or vulnerabilities into the production environment. This can directly lead to system instability, unexpected failures, data corruption, or service outages, which are often more severe than the original emergency condition. While documentation might exist, it doesn't mitigate the technical risk of an untested change.

Why the other options are wrong

  • A. Unauthorized access is a general security risk, but bypassing change control primarily impacts system stability from within, not external attacks.
  • B. While regulatory compliance can be an issue, the most immediate and critical operational risk is the instability of the system itself.
  • D. Inefficient resource allocation is a project management or operational efficiency concern, less critical than potential system outages.

Emergency Change Control

A process for managing urgent system changes that deviate from standard procedures due to immediate operational necessity, while still aiming to minimize risk.

  • Requires post-implementation documentation and review.
  • Should have defined criteria for 'emergency'.
  • Testing and approval should be performed as much as possible, or compensatory controls used.
  • Risk of instability is high if controls are bypassed.

Memory trick: Emergency Changes: Untested = Unstable.

More Domain 3: Information Systems Acquisition, Development and Implementation questions