โ† All CISA Flashcard Decks

Change Management Controls Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Change Management Controls flashcards as text
  1. An IS auditor discovers that emergency changes are being applied directly to production without post-implementation review. What is the PRIMARY risk?

    Answer: Unauthorized or erroneous changes may persist without detection

    Without post-implementation review, emergency changes that introduce errors or unauthorized modifications may remain undetected indefinitely.

  2. Which document formally records the expected and actual outcomes of a system change, supporting rollback decisions?

    Answer: Post-implementation review report

    A post-implementation review report compares expected outcomes with actual results and determines whether rollback or remediation is needed.

  3. A change management policy requires that all code changes be reviewed by a developer other than the author. This control PRIMARILY addresses which risk?

    Answer: Unauthorized or fraudulent code being introduced

    Peer code review provides separation of duties, reducing the risk that a single developer could introduce malicious or erroneous code undetected.

  4. In a change management process, the configuration management database (CMDB) is BEST used to:

    Answer: Track relationships and dependencies between IT components

    The CMDB tracks configuration items and their interdependencies, helping assess the potential impact of proposed changes.

  5. An auditor finds that the change management log shows 40% of changes classified as 'emergency' over the past quarter. What should the auditor conclude FIRST?

    Answer: The classification criteria for emergency changes may be too broad or misused

    A high proportion of emergency changes suggests that standard change controls may be routinely bypassed by misclassifying changes, warranting further investigation.

  6. Which change management control BEST ensures that production libraries are only updated by authorized personnel?

    Answer: Version control system with role-based access controls

    Role-based access controls on version control systems restrict who can commit or deploy code, directly enforcing authorization requirements.

  7. During an audit, an IS auditor verifies that all changes go through a test environment before production. What additional control should the auditor look for?

    Answer: That the test environment is identical or representative of production

    If the test environment does not adequately mirror production, testing results may not predict production behavior, undermining the control.