ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceMedium
During an audit of an organization's change management process, an IS auditor observes that emergency changes are frequently implemented without prior testing in a non-production environment. Which of the following is the PRIMARY risk associated with this practice?
- ADifficulty in tracking the total number of changes implemented.
- BNon-compliance with internal IT policies and procedures.
- CIncreased administrative overhead for change documentation.
- DHigher likelihood of system instability or service disruption.
Show answer & explanationAnswer & explanation
Correct answer: D. Higher likelihood of system instability or service disruption.
Implementing changes without prior testing, especially emergency changes that are often time-sensitive and complex, significantly increases the risk of introducing errors, leading to system instability, outages, or security vulnerabilities in the production environment.
Why the other options are wrong
- A. Tracking can be a challenge, but system instability poses a more direct and severe operational risk.
- B. Non-compliance is a consequence, but the underlying operational risk of instability is the primary concern that leads to non-compliance.
- C. While documentation might suffer, the primary risk is operational, not administrative overhead.
Untested Changes Risk
The inherent danger of deploying modifications to production systems without prior validation in a controlled, non-production environment.
- Directly impacts system stability and availability.
- Can introduce new bugs or security vulnerabilities.
- Increases the likelihood of service disruption and downtime.
Memory trick: Don't jump in the pool before checking the water depth.