easyMultiple Choice
Segregation of Duties in Change Management: Key Control Weakness
An IS auditor is evaluating the effectiveness of an organization's change management process. Which of the following is the most important control to verify during the audit?
⚠ Common exam trap
The trap here is that candidates often focus on approval or prioritization controls (options A and D) as the most important, overlooking the foundational technical control of segregation of duties that directly prevents unauthorized code from reaching production.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A segregation of duties exists between development and production.
Segregation of duties between development and production environments ensures that code cannot be directly moved from development to production without independent review and testing. This control prevents unauthorized or untested code from affecting live systems, which is a fundamental principle of change management. Without this separation, a developer could introduce malicious or defective code directly into production, bypassing all quality and security checks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All changes are approved by the IT manager.
Why it's wrong here
Approval resting solely with the IT manager concentrates authority and omits business-owner sign-off, so segregation of duties and accountability for user-facing changes are unverified. It tempts because approval is genuinely central to change management, yet the correct control requires approval by the appropriate authorised owner.
- ✗
Emergency changes are documented after implementation.
Why it's wrong here
Documenting emergency changes only after implementation removes the pre-implementation authorisation and testing evidence the audit must verify. It tempts because emergency changes are legitimately fast-tracked, but even then retrospective documentation must be paired with prior approval and post-implementation review.
- ✓
A segregation of duties exists between development and production.
Why this is correct
Segregation of duties between development and production prevents developers from promoting their own code, which is the control that most directly mitigates unauthorised or untested changes. Verifying this separation confirms the change management process enforces independent review and approval before production deployment.
- ✗
Change requests are prioritized by business impact.
Why it's wrong here
Prioritisation by business impact governs scheduling, not authorisation; the auditor's primary control is evidence that changes are approved before implementation by the appropriate authority. It tempts because impact ranking supports risk-based approval, but it cannot substitute for the approval gate itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.