An IS auditor is assessing a recent migration of mission critical applications to a virtual platform.
Which of the following observations poses the GREATEST risk to the organization?
Click on the arrows to vote for the correct answer
A. B. C. D.D.
The migration of mission-critical applications to a virtual platform presents several risks to the organization. Therefore, the IS auditor must assess the implementation process to ensure that risks have been identified and addressed.
Out of the four options provided, the observation that poses the greatest risk to the organization is option C, "The migration was not approved by the board of directors." This is because the migration of mission-critical applications to a new platform, especially a virtual platform, is a significant change that impacts the organization's overall operations and may affect its ability to achieve its objectives. It may also introduce new risks, including security risks, that the board of directors should be aware of and provide approval for.
Without approval from the board of directors, the organization may be operating outside its approved risk management framework, and this poses a significant risk to the organization. The board of directors is responsible for providing oversight and governance of the organization's operations and approving significant changes such as the migration of mission-critical applications to a new platform. Therefore, the absence of board approval represents a major risk that should be addressed.
While the other options pose risks, they are not as significant as option C. Option A, "A post-implementation review of the hypervisor has not yet been conducted," represents a risk that can be addressed through a review of the hypervisor post-implementation. Option B, "Role descriptions do not accurately reflect new virtualization responsibilities," is a risk that can be addressed through an update of role descriptions. Finally, option D, "Training for staff with new virtualization responsibilities has not been conducted," represents a risk that can be addressed through training staff on their new responsibilities.
In conclusion, the absence of board approval for the migration of mission-critical applications to a virtual platform represents the greatest risk to the organization out of the options provided. The IS auditor should recommend that the organization seek board approval for the migration as soon as possible to mitigate this risk.