IS 監査人がアプリケーション システムの変更管理に関するドキュメントをレビューし、実稼働前にテストされていないパッチをいくつか特定しました。この状況から生じる最も重大なリスクは次のどれですか。
正解:B
The most significant risk from not testing patches before putting them into production is the lack of system integrity. Patches are software updates that fix bugs, vulnerabilities or performance issues in an application system. However, patches may also introduce new errors, conflicts or compatibility issues that could affect thefunctionality, reliability or security of the system4. By not testing patches before putting them into production, the organization exposes itself to the risk of system failures, data corruption or unauthorized access. Loss of application support, outdated system documentation and developer access to production are also risks from not testing patches, but they are not as significant as the lack of system integrity. References:
* CISA Review Manual, 27th Edition, page 2951
* CISA Review Questions, Answers &Explanations Database - 12 Month Subscription