失敗し、再実装が必要となるソフトウェア変更の数を監視するための主要業績評価指標(KPI)が設定されています。KPIの上昇は、以下の点が効果的でないことを示します。
正解:B
Software change failures typically reflect weaknesses in preventive controls, such as code reviews, approval workflows, and test procedures. Preventive controls are designed to ensure defect-free changes before they reach production. An increase in failed changes indicates these safeguards are not functioning properly.
Corrective controls respond after failures, not before them. Administrative controls (policies and standards) guide behavior but do not directly prevent implementation errors. Deterrent controls are intended to discourage malicious behavior, not prevent unintentional change failures. Therefore, ineffective preventive controls are the root cause indicated by the KPI trend.
Reference: CRISC Review Manual - Control Types (preventive vs corrective vs detective).