ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceMedium

An IS auditor is assessing an organization's change management process. The auditor notes that emergency changes are frequently implemented without thorough testing or formal approval, bypassing the standard change control board (CCB) review. While these changes often resolve immediate issues, they occasionally introduce new, severe defects that lead to further incidents. Which of the following recommendations should the IS auditor make to BEST mitigate this risk without unduly hindering emergency response?

  1. AEstablish a post-implementation review and approval process for emergency changes with clear accountability.
  2. BEliminate all emergency changes and mandate standard change procedures for all modifications.
  3. CRequire all emergency changes to be fully documented and approved by the CCB BEFORE implementation.
  4. DIncrease the number of CCB members to expedite the approval of emergency changes.
Show answer & explanation

Correct answer: A. Establish a post-implementation review and approval process for emergency changes with clear accountability.

Emergency changes often require rapid deployment, making pre-approval and full testing impractical. A post-implementation review and approval process ensures accountability and allows for retrospective validation, defect analysis, and formal recording, mitigating risks without hindering immediate response.

Why the other options are wrong

  • B. Eliminating emergency changes is impractical for critical systems that require immediate fixes, as it would cause more severe downtime.
  • C. Requiring full pre-implementation approval and testing for true emergencies defeats the purpose of an emergency change, which needs speed.
  • D. Increasing CCB members may not address the need for rapid deployment and could still cause delays if full pre-approval is required.

Emergency Change Procedure

A streamlined process for implementing urgent changes to resolve critical incidents or prevent service degradation, often with reduced pre-authorization and testing, but with mandatory post-implementation review.

  • Prioritizes speed for critical issues.
  • Requires post-implementation review and documentation.
  • Balances risk mitigation with rapid response.

Memory trick: Fix fast, review later, but don't forget the paper.

More Domain 4: Information Systems Operations and Business Resilience questions