ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationHard

An IS auditor is reviewing the change management process for a database supporting a critical financial application. The auditor notes that all database schema changes are approved by the application owner, but there is no independent review or testing of the changes before they are applied to production. Which of the following is the MOST significant control weakness?

  1. AInsufficient segregation of duties.
  2. BAbsence of a dedicated database administrator (DBA) role.
  3. CInadequate logging of database changes.
  4. DLack of a formal change advisory board (CAB).
Show answer & explanation

Correct answer: A. Insufficient segregation of duties.

While application owner approval is a form of control, the absence of independent technical review and testing before production deployment represents a critical breakdown in segregation of duties. The application owner, while knowing the business need, may not have the technical expertise to validate the schema change's correctness or impact, and without independent review and testing, errors can easily propagate to production.

Why the other options are wrong

  • B. The question implies a DBA or similar role exists implicitly or explicitly, but the issue is the lack of independent review/testing from that role, not its absence.
  • C. Logging helps detect issues after they occur, but it doesn't prevent erroneous changes from being introduced.
  • D. A CAB is a good practice, but the core issue is the lack of independent technical validation, which can exist even without a formal CAB.

Database Change Controls

Database change controls are processes and procedures designed to manage, approve, test, and implement modifications to database schemas, data, and configurations securely and reliably.

  • Includes approval, testing, and deployment steps.
  • Aims to maintain data integrity and system stability.
  • Requires segregation of duties for critical roles.

Memory trick: Database Changes: Approve, Review, Test, Deploy.

More Domain 3: Information Systems Acquisition, Development and Implementation questions