CPA · Question 30 · Area I: Information Systems
An auditor is reviewing the 'Change Management' process. They observe that emergency changes are allowed to bypass the standard testing phase to restore service quickly. What is the compensating control that MUST be in place for this process to be acceptable?
Answer options:
Pre-approval by the CEO.
Post-implementation review and retrospective approval
No control is needed for emergencies.
The developer must have admin access permanently.
82 questions · hints · full answers · grading