Which Incident Management Change Concerns an IS Auditor?

Incident Management & IT Service Controls
Answer Correct answer: B — Enabling reporters to assign ticket priority introduces subjective classification risks that compromise standardized incident triage controls.

Which of the following changes intended to improve and streamline an organization's incident management process would be a potential concern to an IS auditor?

  1. Implementing automatic reporting for all open incidents over three months old
  2. Enabling the capability for the individual reporting the incident to assign priority to a ticket Correct Answer
  3. Configuring automated messaging to service lines notifying them of the status of the ticket
  4. Introducing self-service functions for selected low-complexity incident types

Community Votes

B
67%
A
33%

67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the balance between process efficiency and audit controls, with the common trap being the assumption that user empowerment automatically improves incident handling.

Allowing end-users to assign ticket priorities undermines standardized triage controls, making it a primary audit concern despite streamlining efforts. Community consensus confirms that subjective prioritization introduces classification risks that outweigh operational convenience.

Option A is frequently selected because aging incident reports appear risky, but automated visibility actually strengthens accountability rather than creating control gaps.

Community Discussion (4 comments)

Swallows 👍 2 Selected: B
Allowing individual reporters to determine priority runs the risk of subjective judgment and not prioritizing important incidents appropriately, which can lead to less efficient incident management and resolution.
Swallows 👍 1
B. Enabling the ability for individuals who report incidents to assign priorities to tickets This change is generally expected to have a positive impact as it promotes effective incident management and prioritization. It is expected that reporters will evaluate the importance and urgency of the incident and respond accordingly. Therefore, the change that is of potential concern to IS auditors is "A. Implementing automated reporting for all open incidents older than three months." If this change is not managed properly, there is a risk that it will affect the effectiveness of incident management and the credibility of the organization.
joehong 👍 1 Selected: A
Should be a
Sibsankar 👍 1
option A does indeed present potential concerns regarding the accuracy and context of reporting for aging incidents. While it aims to improve transparency and accountability, there is a risk of misrepresentation if not implemented carefully.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Granting reporters the authority to set ticket priority bypasses established impact-urgency matrices, introducing subjective judgment into critical triage workflows. IS auditors prioritize standardized classification to ensure SLA compliance, accurate resource allocation, and consistent risk assessment across the organization. Without centralized control, high-severity issues may be downgraded while minor requests are escalated unnecessarily.

Why the Other Options Are Wrong

Automated reporting for aging tickets (Option A) increases transparency and helps management identify bottlenecks, which auditors generally favor as a monitoring control. Automated status notifications (Option C) improve communication and tracking without altering decision-making authority. Self-service resolution for low-complexity cases (Option D) reduces analyst workload and is explicitly encouraged in modern ITIL frameworks when properly scoped.

Community Comment Notes

Multiple contributors highlight that reporter-assigned prioritization leads to inconsistent severity mapping and potential SLA violations. One comment correctly notes that subjective judgment compromises efficient incident management, reinforcing the need for trained service desk analysts to handle classification. Another discussion acknowledges aging report risks but correctly identifies them as manageable rather than fundamentally flawed controls.

Official Reference

Exam Strategy

Always evaluate proposed process changes through an audit lens, weighing efficiency gains against control degradation. If a modification removes managerial oversight or introduces subjective decision-making at a critical control point, flag it as a potential audit concern regardless of its operational appeal.

Frequently Asked Questions

Why is automated aging reporting not an audit concern?

It enhances management visibility and accountability for unresolved tickets, which auditors view as a positive monitoring control rather than a risk.

Can self-service incident resolution ever violate audit standards?

Only when applied to complex or security-sensitive cases; limiting it to low-complexity types maintains proper scope and control boundaries.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide