An IS auditor discovers that emergency changes are being applied directly to production without post-implementation review. What is the PRIMARY risk?
-
A
Emergency changes are inherently too risky to permit
-
B
Unauthorized or erroneous changes may persist without detection
-
C
Developers gain permanent elevated privileges
-
D
Change advisory boards become unnecessary