QuestionQ66

Information Systems Operations and Business Resilience

Which of the following would be of GREATEST concern to an IS auditor assessing an organization’s configuration and release management process?

Explanation

Configuration and release management requires documented changes and recorded approvals to provide an audit trail and demonstrate that changes were authorized and controlled. Without that documentation, unauthorized or inadequately reviewed changes may be implemented without accountability.

Community Discussion

No comments yet. Be the first to start the discussion!