ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceEasy
During an audit of an organization's information systems operations, an IS auditor observes that critical system upgrades are frequently delayed due to unforeseen compatibility issues with existing applications. These delays often result in extended downtime and operational disruptions. Which of the following areas should the IS auditor recommend strengthening FIRST to address this recurring problem?
- AProviding additional end-user training on new system functionalities post-upgrade.
- BEnhancing incident response procedures for faster resolution of compatibility issues.
- CIncreasing the frequency of system backups to minimize data loss during upgrades.
- DImplementing a more robust testing and quality assurance (QA) process for changes.
Show answer & explanationAnswer & explanation
Correct answer: D. Implementing a more robust testing and quality assurance (QA) process for changes.
Frequent compatibility issues indicate a weakness in the pre-implementation testing phase. A robust testing and QA process would identify these issues before they impact live operations, preventing delays and disruptions.
Why the other options are wrong
- A. End-user training addresses user adoption, not the underlying technical compatibility problems causing delays.
- B. Incident response is reactive; strengthening proactive measures is more effective for recurring issues.
- C. Increased backups are a good practice for recovery but do not prevent the compatibility issues themselves.
Change Management Testing
The process of verifying that proposed changes to an information system will function as intended and will not adversely affect existing systems or operations.
- Identifies compatibility issues proactively.
- Reduces risk of operational disruption.
- Ensures stability and reliability of systems after changes.
Memory trick: Test before you trust, or your system will rust.