ある組織は、IT サービス提供全体のパフォーマンスを向上させるために、ビジネス プロセスを再設計することを決定しました。プロジェクト チームからの次の推奨事項のうち、IS 監査人が最も懸念すべきものはどれですか。
正解:A
Disabling operational logging compromises critical functions such as security monitoring, troubleshooting, and compliance reporting. Logs are essential for tracking system activities, identifying anomalies, and conducting forensic investigations in case of incidents. Enhancing processing speed and saving storage should not come at the cost of reducing logging, as this increases security risks and weakens the organization's ability to detect and respond to threats.
* Adopting a Peer-Inspired Service Delivery Model (Option B):This might pose risks if not customized for the organization's context, but it is not as critical as the loss of operational logging.
* Delegating Business Decisions to the CRO (Option C):While unconventional, this does not inherently introduce risks to IT service delivery unless operational control issues arise.
* Eliminating Reports and KPIs (Option D):This could hinder performance tracking but does not compromise operational security as severely as disabling logging.
Operational logging is foundational to maintaining security, reliability, and accountability in IT environments.
Reference:ISACA CISA Review Manual, Job Practice Area 3: Information Systems Operations and Business Resilience.