Auditor Next Step After Release-Related Production Incident
An IS auditor noted a recent production incident in which a teller transaction system incorrectly charged fees to customers due to a defect from a recent release. Which of the following should be the auditor's NEXT step?
Community Votes
50% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the auditor’s ability to trace a production defect back to its lifecycle stage, with the common trap being an immediate focus on incident response instead of the underlying release control failure.
This CISA question tests whether auditors prioritize incident response or change control after a release-caused defect. While community votes split evenly, expert analysis confirms evaluating the change management process is the correct next step to address the root cause.
Option C is frequently chosen because auditors instinctively look at incident handling first, but it misses the explicit clue that the defect originated from a recent release, making change management the higher-priority audit area.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct choice is D because the question explicitly states the defect stemmed from a recent release. In CISA methodology, any production error linked to a deployment must trigger a review of the change management process, which governs testing, approval, and rollout controls. Evaluating this process determines whether safeguards like user acceptance testing or rollback procedures failed.Why the Other Options Are Wrong
Option A and B focus on developer capabilities rather than organizational controls, which are outside the scope of an immediate post-incident audit step. Option C addresses how the team responded to the outage, but does not investigate why the defective code passed through deployment gates. Auditors prioritize prevention and control validation over reactive measures when the root cause is clearly identified.Community Comment Notes
Several top-voted comments correctly identify D as the answer, noting that insufficient testing during the release phase points directly to change management gaps (Comment 2, 3, 4). Others argue for C based on standard incident response protocols, highlighting why candidates often split their votes. The consensus among experienced IS auditors aligns with tracing defects to their source control point before assessing response effectiveness.Official Reference
Exam Strategy
When a CISA question mentions a defect tied to a 'recent release,' 'deployment,' or 'patch,' immediately map it to change management controls. Prioritize reviewing testing, approvals, and rollback procedures in your audit steps, as ISACA consistently tests control ownership over lifecycle stages rather than generic response workflows.
Frequently Asked Questions
Why not evaluate incident management first?
Incident management handles response and recovery, but the question explicitly ties the defect to a recent release. Auditors prioritize tracing the root cause to change controls for prevention.
Does change management include software testing?
Yes. CISA classifies requirement analysis, code review, user acceptance testing, and deployment approvals under the change management lifecycle, making it the correct audit focus here.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →