ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceMedium

During an audit of an organization's change management process, an IS auditor observes that emergency changes are frequently implemented without prior testing in a non-production environment. Which of the following is the PRIMARY risk associated with this practice?

  1. ADifficulty in tracking the total number of changes implemented.
  2. BNon-compliance with internal IT policies and procedures.
  3. CIncreased administrative overhead for change documentation.
  4. DHigher likelihood of system instability or service disruption.
Show answer & explanation

Correct answer: D. Higher likelihood of system instability or service disruption.

Implementing changes without prior testing, especially emergency changes that are often time-sensitive and complex, significantly increases the risk of introducing errors, leading to system instability, outages, or security vulnerabilities in the production environment.

Why the other options are wrong

  • A. Tracking can be a challenge, but system instability poses a more direct and severe operational risk.
  • B. Non-compliance is a consequence, but the underlying operational risk of instability is the primary concern that leads to non-compliance.
  • C. While documentation might suffer, the primary risk is operational, not administrative overhead.

Untested Changes Risk

The inherent danger of deploying modifications to production systems without prior validation in a controlled, non-production environment.

  • Directly impacts system stability and availability.
  • Can introduce new bugs or security vulnerabilities.
  • Increases the likelihood of service disruption and downtime.

Memory trick: Don't jump in the pool before checking the water depth.

More Domain 4: Information Systems Operations and Business Resilience questions