IS 監査人は、最近のリリースの欠陥により、出納係取引システムが顧客に誤って料金を請求するという最近の製造インシデントに気付きました。監査人が次に取るべきステップは次のどれですか。
正解:C
The change management process is the set of procedures and activities that ensure that changes to the information system are authorized, tested, documented, and implemented in a controlled manner12. A defect in a recent release indicates that there may be issues with the quality assurance, testing, or approval of the changes, which could affect the reliability, security, and performance of the system3 . Therefore, the auditor's next step should be to evaluate the change management process and identify the root cause of the defect, as well as the impact and remediation of the incident.
References
1: Change Management - CISA
2: What is Change Management? - Definition from Techopedia
3: How to Audit Change Management - ISACA Journal
The Business Case for Security | CISA