Which Control Best Prevents Unapproved Emergency Changes to a Critical System?

Information Systems Operations and Business Resilience (Change Management)
Answer Correct answer: D — Deploy dual-control temporary emergency access accounts so no single administrator can execute unapproved emergency changes alone.

A business area received an audit finding because an administrator made unapproved emergency changes to a critical system. Which of the following would BEST prevent unapproved changes in the future?

  1. Two-factor authentication on emergency access accounts
  2. Updated emergency change management procedures
  3. Regular emergency change-control log reviews
  4. Dual-control temporary emergency access accounts Correct Answer

Community Votes

D
67%
B
33%

67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests selecting a preventive control over a detective or administrative one: dual control physically blocks unilateral changes, while the trap is choosing procedure updates, which guide behavior but do not enforce approval.

This CISA question contrasts preventive and detective controls in emergency change management, where dual-control temporary emergency access accounts stop any single administrator from acting unilaterally on a critical system. The community favors D over updated procedures by roughly a two-to-one margin, consistent with ISACA's preference for enforced preventive controls.

About a third of voters chose B (updated emergency change management procedures), reasoning that controls fail without a defined process; however, procedures alone are administrative guidance that cannot stop an administrator from bypassing approval, so they do not BEST prevent recurrence.

Community Discussion (5 comments)

blehbleh 👍 2 Selected: B
I vote B, you need clearly defined procedures. I understand D as an extra control. But if there are still no procedures in place that explain how something is supposed to be done or how to correctly do things you are just adding a control without informing anyone how to conduct the work. So should an emergency change be required again two people could very easily just do an emergency change again without following any procedures because they were still never created.
RS66 👍 2 Selected: D
D. Dual-control temporary emergency access accounts
4dfe785 👍 2 Selected: D
Dual-control (or two-person integrity) requires two individuals to authorize and execute actions. By implementing dual-control for emergency access accounts, it ensures that no single administrator can make changes without the approval of another authorized individual. This significantly reduces the risk of unapproved changes as it requires collaboration and oversight, providing a robust mechanism for preventing unauthorized actions.
Swallows 👍 1 Selected: B
To most effectively prevent unauthorized emergency changes, B. Updating emergency change management procedures is the best option. The reason is that clearly defining procedures and reinforcing the necessary approval processes will encourage managers to follow proper procedures when making changes. This will reduce the risk of unauthorized changes occurring in the future. D. "Dual-control temporary emergency access accounts" is also effective, but a review of fundamental procedures should be prioritized.
joehong 👍 2 Selected: D
Dual-control accounts require two individuals to authorize and execute changes, which significantly reduces the risk of unapproved changes.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Dual-control temporary emergency access accounts implement two-person integrity, meaning no single administrator can invoke emergency access and push changes to a critical system without a second authorized individual authorizing and executing the action. This is a preventive control that directly removes the root cause identified in the audit finding — one administrator acting unilaterally. Because the accounts are temporary, standing privileged access is also minimized, shrinking the window for misuse. ISACA consistently ranks technical preventive controls above procedural guidance when a question asks what BEST prevents recurrence.

Why the Other Options Are Wrong

Two-factor authentication (A) verifies identity but does nothing to restrict what an authenticated administrator can do, so an approved admin can still make unapproved changes alone. Updated emergency change management procedures (B) are valuable but purely administrative; a policy statement cannot physically stop an administrator from bypassing approval, which is exactly what already happened. Regular emergency change-control log reviews (C) are detective controls that surface violations only after changes have occurred, failing the explicit "prevent" requirement. Only D inserts an enforcement checkpoint before a change can be executed.

Community Comment Notes

Comments [3] and [4] articulate the winning logic — dual control "requires two individuals to authorize and execute actions," which significantly reduces the risk of unapproved changes. The minority camp, represented by comments [1] and [5], argues procedures must first define how emergency work is performed, but even comment [1] concedes D functions as an added control on top of process. The vote distribution (D: 67, B: 33) shows a clear two-to-one community consensus for the enforcement-based option. This split mirrors a classic CISA debate between documented process and enforced control, with ISACA favoring enforcement for preventive questions.

Official Reference

Exam Strategy

When a CISA question asks which control BEST prevents something, pick the option that technically enforces the desired behavior rather than one that documents or detects it. Dual control (two-person integrity) physically requires a second person before an emergency change can execute. Procedure updates and log reviews support the control environment but operate around or after the event.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide