CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 283


In a small IT web development company where developers must have write access to production, the BEST recommendation of an IS auditor would be to:

Show Answer
Correct Answer: D

In a small IT web development company where developers must have write access to production, the best recommendation of an IS auditor would be to remove production access from the developers. This principle of separation of duties is a fundamental security control aimed at reducing the risk of unauthorized or erroneous changes to the production environment. By ensuring that developers do not have direct access to production, the risk of accidental or malicious changes is minimized, and the integrity of the production environment is better maintained.

Discussion

4 comments
Sign in to comment
ChangwhaOption: D
Jul 16, 2023

D. remove production access from the developers.

3008Option: C
Jul 30, 2023

C is answer.

munchhhOption: C
Jan 25, 2024

C is the answer

SwallowsOption: C
Jun 2, 2024

Continuous monitoring provides a proactive and ongoing mechanism to monitor and safeguard production environments against security threats and unauthorized activities. It complements other security measures and helps ensure the integrity and security of production systems in a dynamic development environment. Therefore, it can be considered the BEST recommendation by an IS auditor in this scenario.