Which of the following tests performed by an IS auditor would be the MOST effective in determining compliance with an organization’s change control procedures?

Which of the following tests performed by an IS auditor would be the MOST effective in determining compliance with an organization’s change control procedures?

Which of the following tests performed by an IS auditor would be the MOST effective in determining compliance with an organization’s change control procedures?

Review software migration records and verify approvals.

identify changes that have occurred and verify approvals.

Review change control documentation and verify approvals.

Ensure that only appropriate staff can migrate changes into production.

The most effective method is to determine through code comparisons what changes have been made and then verify that they have been approved. Change control records and software migration records may not have all changes listed. Ensuring that only appropriate staff can migrate changes into production is a key control process, but in itself does not verify compliance.

Leave a Reply 0

Your email address will not be published. Required fields are marked *