QuestionQ119

Information System Auditing Process

An IS auditor is examining a recent security incident and needs information about the authorization of a recent change to a database system’s security settings. Where would the auditor MOST likely locate this information?

Explanation

A change log is part of the change-management record and documents configuration changes along with their authorization or approval status. Security and database event logs capture activity and events, but do not normally serve as the formal record of change approval.

Community Discussion

No comments yet. Be the first to start the discussion!