An IS auditor is evaluating the organization's release management process. The auditor notes that new software releases are deployed directly to production systems without a formal 'go/no-go' decision point involving key stakeholders. Which of the following is the MOST critical risk introduced by this practice?
- ALack of proper communication about release schedules to end-users.
- BDifficulty in maintaining an accurate inventory of deployed software versions.
- CIncreased burden on the development team for post-release support.
- DDeployment of releases that do not meet business requirements or quality standards.
Show answer & explanationAnswer & explanation
Correct answer: D. Deployment of releases that do not meet business requirements or quality standards.
A formal 'go/no-go' decision point, typically involving stakeholders like business owners, operations, and quality assurance, is crucial to ensure that a release is ready for production. Bypassing this step significantly increases the risk of deploying software that is buggy, unstable, or does not align with business needs, leading to operational issues and negative business impact.
Why the other options are wrong
- A. Communication is vital, but deploying an unvetted release has a more severe impact than just lack of notification.
- B. Version control is important but is a secondary concern compared to the fundamental risk of deploying flawed software.
- C. While possible, the primary risk is the quality and suitability of the release itself, not just who supports it.
Missing Go/No-Go Risk
The hazard of deploying software releases to production without a formal, stakeholder-approved decision point, leading to potential quality issues, non-compliance, and business disruption.
- Ensures releases meet business and quality standards.
- Mitigates risks of deploying faulty software.
- Involves cross-functional stakeholder review.
Memory trick: Launching a rocket without checking all the pre-flight checklists.