CRISC Exam Question: IT Business Owner's Best Course of Action | Certified Risk and Information Systems Control

IT Business Owner's Best Course of Action Following Unexpected Increase in Emergency Changes

Prev Question Next Question

Question

Which of the following would be an IT business owner's BEST course of action following an unexpected increase in emergency changes?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

A.

An unexpected increase in emergency changes can indicate a breakdown in the IT change management process. As such, the IT business owner needs to take appropriate measures to address the issue and prevent it from recurring in the future.

A. Conducting a root-cause analysis:

This would involve identifying the underlying cause(s) of the increase in emergency changes. By conducting a root-cause analysis, the IT business owner can determine if there are any systemic issues that need to be addressed. For example, the increase in emergency changes could be due to inadequate change management policies or a lack of training for IT staff. By addressing the root cause(s), the IT business owner can reduce the likelihood of future emergencies.

B. Validating the adequacy of current processes:

This would involve reviewing the existing IT change management processes to ensure they are adequate. The IT business owner would need to examine the policies, procedures, and tools currently in use to manage changes. This would help to identify any areas that need improvement, such as a lack of documentation or inadequate testing procedures.

C. Evaluating the impact to control objectives:

This would involve assessing the impact of the increase in emergency changes on the organization's control objectives. For example, if emergency changes are being made without proper documentation, this could pose a risk to the integrity of the organization's systems. By evaluating the impact to control objectives, the IT business owner can determine if any additional measures need to be taken to mitigate these risks.

D. Reconfiguring the IT infrastructure:

This would involve making changes to the organization's IT infrastructure to address the increase in emergency changes. However, this option may not be the best course of action, as it does not address the underlying cause(s) of the increase. Additionally, reconfiguring the IT infrastructure can be expensive and time-consuming.

In conclusion, the best course of action for an IT business owner following an unexpected increase in emergency changes would be to conduct a root-cause analysis. This would help to identify the underlying cause(s) of the increase and allow the IT business owner to take appropriate measures to prevent it from recurring in the future. Additionally, validating the adequacy of current processes and evaluating the impact to control objectives can help to ensure that the organization's IT change management process is effective and meets its control objectives.