ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceMedium
An IS auditor is evaluating the organization's information systems operations. The auditor observes that critical system patches are deployed without a formal impact assessment or prior approval from stakeholders. What is the MOST significant risk posed by this practice?
- AInconsistent application of security policies across systems.
- BDifficulty in rolling back patches if issues arise post-deployment.
- CIntroduction of system instability or functional defects into production.
- DNon-compliance with software vendor support agreements.
Show answer & explanationAnswer & explanation
Correct answer: C. Introduction of system instability or functional defects into production.
Deploying patches without impact assessment or approval means potential conflicts, incompatibilities, or unexpected behavior are not identified before deployment. This significantly increases the risk of introducing instability or functional defects into critical production systems, disrupting operations.
Why the other options are wrong
- A. Inconsistent policy application is a broader governance issue, not directly caused by skipping patch impact assessment.
- B. Difficulty in rollback is a consequence of poor planning, but the primary risk is that issues are introduced in the first place without proper assessment.
- D. While a minor risk, the direct operational impact of a failed patch is more significant.
Patch Management Process
The systematic process of identifying, acquiring, testing, deploying, and verifying software patches to maintain system security and functionality.
- Crucial for addressing vulnerabilities and improving performance.
- Requires formal assessment, testing, and approval steps.
- Part of a broader change management framework.
Memory trick: Patching without assessment is like surgery without diagnosis; you might make things worse.