Which of the following observations should be of GREATEST concern to an IS auditor performing an audit of change and release management controls for a new complex system developed by a small in-house IT team?
A.
IT administrators have access to the production and development environment.
B.
Some user acceptance testing (UAT) was completed by members of the IT team.
C.
Post-implementation testing is not conducted for all system releases.
D.
Access to change testing strategy and results is not restricted to staff outside the IT team.
Post-implementation testing is crucial in identifying and resolving any defects, errors, or problems that may have occurred during deployment or were missed during previous testing phases. The IT administrator's access to the operational and development environments is not a concern for information technology auditors. IT administrators are accountable for managing and maintaining the IT infrastructure, including the operational and development environments. It is absolutely necessary for employees to have access to both environments, provided they adhere to the appropriate policies and procedures for access, use, and protection. Furthermore, IT administrators must perform essential tasks such as backup, restore, patching, and troubleshooting in both environments.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
PurpleParrot
2 months, 1 week agoSwallows
7 months, 4 weeks ago