CISA Change Management Controls 5 β Questions and Answers
Question 1: An IS auditor is evaluating whether change management controls adequately protect against insider threats. The MOST effective control is:
- Requiring all staff to complete annual security awareness training
- Enforcing dual authorization for high-impact production changes (Correct answer)
- Conducting background checks at time of hire
- Using encrypted communication channels for change notifications
Correct answer: Enforcing dual authorization for high-impact production changes
Dual authorization requires two authorized individuals to approve or execute high-impact changes, significantly reducing the ability of a single insider to cause harm.
Question 2: A company migrates to a cloud platform where the provider manages infrastructure changes. The IS auditor should verify that:
- The company's internal CAB approves all cloud provider changes
- The company's SLA includes notification and communication of provider-side changes (Correct answer)
- The company replicates the provider's change management process internally
- The cloud provider's changes are exempt from audit scrutiny
Correct answer: The company's SLA includes notification and communication of provider-side changes
SLA provisions for change notification ensure that cloud provider-initiated changes do not surprise the organization or violate agreed service expectations.
Question 3: An organization's change management policy states that all changes must have a business justification. What risk does this control PRIMARILY mitigate?
- Technical failures caused by untested code
- Unnecessary or unauthorized changes that increase system complexity and risk (Correct answer)
- Inadequate post-implementation monitoring
- Lack of stakeholder awareness about system modifications
Correct answer: Unnecessary or unauthorized changes that increase system complexity and risk
Requiring business justification prevents changes that lack a legitimate purpose, reducing system complexity, attack surface, and unnecessary operational risk.
Question 4: Which of the following change management artifacts provides the BEST evidence for an IS audit of compliance with approved procedures?
- Meeting minutes from quarterly IT governance reviews
- Completed change tickets with approval signatures and test results (Correct answer)
- Developer training completion records
- System performance dashboards from the change window
Correct answer: Completed change tickets with approval signatures and test results
Complete change tickets with documented approvals and test results provide direct evidence that each change followed the required authorization and validation steps.
Question 5: During testing of a change management process, an IS auditor selects a sample of changes and finds that 15% have no evidence of user acceptance testing (UAT). The auditor should:
- Accept the finding as immaterial since it is less than 20%
- Determine whether those changes required UAT per policy and assess the impact (Correct answer)
- Recommend immediate suspension of all deployment activity
- Expand the sample to 100% of changes before drawing conclusions
Correct answer: Determine whether those changes required UAT per policy and assess the impact
The auditor must assess whether policy required UAT for those specific changes and evaluate the risk created by omitting it before drawing a conclusion about materiality.
Question 6: What does a change management process that includes a 'back-out trigger' PRIMARILY address?
- The need to approve additional budget for failed changes
- Pre-defined conditions under which a rollback must be initiated without further approval (Correct answer)
- Escalation procedures for unresponsive vendors
- Notification timelines for executive stakeholders
Correct answer: Pre-defined conditions under which a rollback must be initiated without further approval
A back-out trigger specifies objective criteria (e.g., error rate exceeds threshold) that automatically initiate rollback, reducing decision delays during a failed deployment.
Question 7: An IS auditor reviewing change management controls notes that the organization does not track the time between change approval and implementation. Why is this a concern?
- Approved changes may be implemented after their authorization has effectively expired (Correct answer)
- The CAB cannot calculate its approval turnaround KPI
- Developers may forget the technical details of an approved change over time
- Change scheduling conflicts cannot be identified without time tracking
Correct answer: Approved changes may be implemented after their authorization has effectively expired
If changes are implemented long after approval, system conditions may have changed, rendering the original risk assessment and approval invalid.
An IS auditor is evaluating whether change management controls adequately protect against insider threats.
The MOST effective control is: