Which Incident Management Change Concerns an IS Auditor?
Which of the following changes intended to improve and streamline an organization's incident management process would be a potential concern to an IS auditor?
Community Votes
67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the balance between process efficiency and audit controls, with the common trap being the assumption that user empowerment automatically improves incident handling.
Allowing end-users to assign ticket priorities undermines standardized triage controls, making it a primary audit concern despite streamlining efforts. Community consensus confirms that subjective prioritization introduces classification risks that outweigh operational convenience.
Option A is frequently selected because aging incident reports appear risky, but automated visibility actually strengthens accountability rather than creating control gaps.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Granting reporters the authority to set ticket priority bypasses established impact-urgency matrices, introducing subjective judgment into critical triage workflows. IS auditors prioritize standardized classification to ensure SLA compliance, accurate resource allocation, and consistent risk assessment across the organization. Without centralized control, high-severity issues may be downgraded while minor requests are escalated unnecessarily.Why the Other Options Are Wrong
Automated reporting for aging tickets (Option A) increases transparency and helps management identify bottlenecks, which auditors generally favor as a monitoring control. Automated status notifications (Option C) improve communication and tracking without altering decision-making authority. Self-service resolution for low-complexity cases (Option D) reduces analyst workload and is explicitly encouraged in modern ITIL frameworks when properly scoped.Community Comment Notes
Multiple contributors highlight that reporter-assigned prioritization leads to inconsistent severity mapping and potential SLA violations. One comment correctly notes that subjective judgment compromises efficient incident management, reinforcing the need for trained service desk analysts to handle classification. Another discussion acknowledges aging report risks but correctly identifies them as manageable rather than fundamentally flawed controls.Official Reference
Exam Strategy
Always evaluate proposed process changes through an audit lens, weighing efficiency gains against control degradation. If a modification removes managerial oversight or introduces subjective decision-making at a critical control point, flag it as a potential audit concern regardless of its operational appeal.
Frequently Asked Questions
Why is automated aging reporting not an audit concern?
It enhances management visibility and accountability for unresolved tickets, which auditors view as a positive monitoring control rather than a risk.
Can self-service incident resolution ever violate audit standards?
Only when applied to complex or security-sensitive cases; limiting it to low-complexity types maintains proper scope and control boundaries.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →