ある企業では、すべてのプログラム変更要求 (PCR) が承認され、すべての変更が自動的に記録されることを要求しています。次の IS 監査手順のうち、生産プログラムに許可されていない変更が加えられたかどうかを最も適切に判断できるのはどれですか。
正解:B
The best way to determine whether unauthorized changes have been made to production programs is to use source code comparison software to compare the current version of the programs with the previous version or the approved version. This will identify any changes that have been made without proper authorization or documentation. Tracing PCRs to logs or vice versa will only verify that the authorized changes have been recorded, but not detect any unauthorized changes. References: Standards, Guidelines, Tools and Techniques - ISACA, section "IS Audit and Assurance Tools and Techniques"