ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessMedium

An IS auditor is reviewing the effectiveness of an organization's change management process. The audit reveals that a significant number of emergency changes are implemented without proper testing or rollback plans. What is the PRIMARY risk introduced by this finding?

  1. ASystem instability and service disruption.
  2. BDifficulty in tracking changes for future audits.
  3. CIncreased cost of IT operations.
  4. DNon-compliance with internal security policies.
Show answer & explanation

Correct answer: A. System instability and service disruption.

Implementing emergency changes without proper testing or rollback plans significantly increases the likelihood that these changes will introduce errors, conflicts, or vulnerabilities, leading directly to system instability, outages, or service degradation. This is the most immediate and critical operational risk.

Why the other options are wrong

  • B. Difficulty in tracking changes is an audit issue, but not the primary operational risk to the organization's systems.
  • C. Increased costs are a potential consequence, but secondary to direct operational impact.
  • D. While it may indicate non-compliance, the primary *risk* to the business operations is instability.

Untested Changes Risk

The risk associated with deploying system or application changes without adequate testing and/or rollback plans, potentially leading to system instability, errors, security vulnerabilities, or service disruptions.

  • Increases likelihood of unexpected negative impacts.
  • Especially critical for emergency changes.
  • Mitigated by thorough testing and robust rollback procedures.

Memory trick: Change Chaos: Untested Changes Cause Catastrophe.

More Domain 1: Information System Auditing Process questions