CISA Certified Information Systems Auditor – Question2130

Which of the following is the MOST effective way to prevent unauthorized changes from being moved into production?

A.
Conduct periodic review of change tickets to ensure all change documentation is attached.
B. Enforce segregation of duties between developers and migrators.
C. Perform thorough testing of changes in the test environment.
D. Require approval of changes by the appropriate business process owners.

Correct Answer: C