ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceMedium
An IS auditor is evaluating an organization's change management process. The auditor observes that emergency changes are frequently implemented without a formal back-out plan documented prior to implementation. What is the MOST critical risk introduced by this practice?
- AExtended downtime due to inadequate communication during the change.
- BInability to restore the system to a known good state if the change fails.
- CIncreased likelihood of unauthorized changes being introduced.
- DLack of proper testing before the change goes live.
Show answer & explanationAnswer & explanation
Correct answer: B. Inability to restore the system to a known good state if the change fails.
A back-out plan is crucial for emergency changes. Without it, if the change fails or causes unforeseen issues, there is no predefined method to revert the system to its previous stable state, leading to prolonged outages or further complications.
Why the other options are wrong
- A. While communication is important, the primary risk of missing a back-out plan is the inability to recover, not just communication issues.
- C. Unauthorized changes are typically a risk of bypassing the approval process, not directly the absence of a back-out plan.
- D. Lack of testing is a separate, though related, risk. A back-out plan addresses recovery AFTER a change, tested or not, has failed.
Back-out Plan
A documented strategy or set of procedures to reverse a change and restore a system or service to its original operational state if the change fails or causes unexpected issues.
- Essential for risk mitigation in change management.
- Ensures business continuity by providing a recovery path.
- Particularly critical for emergency and high-impact changes.
Memory trick: No back-out plan is like no reverse gear in a car; you're stuck.