โ† All CISA Flashcard Decks

Change Management Controls Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Change Management Controls flashcards as text
  1. An IS auditor is evaluating whether change management controls adequately protect against insider threats. The MOST effective control is:

    Answer: Enforcing dual authorization for high-impact production changes

    Dual authorization requires two authorized individuals to approve or execute high-impact changes, significantly reducing the ability of a single insider to cause harm.

  2. A company migrates to a cloud platform where the provider manages infrastructure changes. The IS auditor should verify that:

    Answer: The company's SLA includes notification and communication of provider-side changes

    SLA provisions for change notification ensure that cloud provider-initiated changes do not surprise the organization or violate agreed service expectations.

  3. An organization's change management policy states that all changes must have a business justification. What risk does this control PRIMARILY mitigate?

    Answer: Unnecessary or unauthorized changes that increase system complexity and risk

    Requiring business justification prevents changes that lack a legitimate purpose, reducing system complexity, attack surface, and unnecessary operational risk.

  4. Which of the following change management artifacts provides the BEST evidence for an IS audit of compliance with approved procedures?

    Answer: Completed change tickets with approval signatures and test results

    Complete change tickets with documented approvals and test results provide direct evidence that each change followed the required authorization and validation steps.

  5. During testing of a change management process, an IS auditor selects a sample of changes and finds that 15% have no evidence of user acceptance testing (UAT). The auditor should:

    Answer: Determine whether those changes required UAT per policy and assess the impact

    The auditor must assess whether policy required UAT for those specific changes and evaluate the risk created by omitting it before drawing a conclusion about materiality.

  6. What does a change management process that includes a 'back-out trigger' PRIMARILY address?

    Answer: Pre-defined conditions under which a rollback must be initiated without further approval

    A back-out trigger specifies objective criteria (e.g., error rate exceeds threshold) that automatically initiate rollback, reducing decision delays during a failed deployment.

  7. An IS auditor reviewing change management controls notes that the organization does not track the time between change approval and implementation. Why is this a concern?

    Answer: Approved changes may be implemented after their authorization has effectively expired

    If changes are implemented long after approval, system conditions may have changed, rendering the original risk assessment and approval invalid.

Change Management Controls Flashcards โ€” CISA Study Cards with Answers