ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceHard
An IS auditor is assessing an organization's configuration management database (CMDB). The auditor finds that while the CMDB accurately lists all IT assets, it lacks established baselines for critical configurations. What is the MOST significant implication of this finding?
- AInability to detect unauthorized or erroneous changes to critical systems.
- BIncreased time required for incident diagnosis and resolution.
- CDifficulty in performing accurate capacity planning for IT resources.
- DChallenges in enforcing software license compliance across the organization.
Show answer & explanationAnswer & explanation
Correct answer: A. Inability to detect unauthorized or erroneous changes to critical systems.
Without established baselines, the organization has no 'known good' state to compare against. This makes it extremely difficult to identify when configurations have been altered, whether accidentally or maliciously, directly impacting the ability to detect unauthorized changes.
Why the other options are wrong
- B. While baselines can aid diagnosis, the primary and most significant implication is the inability to detect unauthorized changes in the first place.
- C. Capacity planning relies on asset details and usage, not directly on configuration baselines.
- D. Software license compliance is related to asset inventory, not specifically to configuration baselines.
Configuration Baseline
A documented and agreed-upon specification for a configuration item (CI) at a specific point in time, serving as a reference for future changes or comparisons.
- Defines the 'known good' state of a system or component.
- Used to detect unauthorized changes or deviations.
- Essential for maintaining system integrity and security.
Memory trick: No baseline is like having no blueprint; you can't tell if the building has changed.