mediumMultiple ChoiceObjective-mapped
Segregation of Duties in Change Management: Key Control Weakness
An IS auditor is reviewing a change management process. A developer made an emergency change directly to production without following the standard change approval process. The change was later documented as a normal change. Which control weakness is MOST indicated by this scenario?
Quick Answer
The answer is inadequate segregation of duties between development and production environments. This is the most significant control weakness because the developer bypassed the standard change approval process by making an emergency change directly to production, then retroactively documenting it as a normal change, which eliminates independent oversight and violates the core principle of segregation of duties. On the CISA exam, this scenario tests your ability to distinguish between a process failure and a fundamental control weakness—many candidates mistakenly focus on the lack of approval rather than the deeper issue of a single individual having both development and production access. A common trap is to select “inadequate change documentation” or “lack of emergency change policy,” but the real risk is that the same person who coded the change also controlled its deployment and audit trail. Memory tip: if one person can touch both the code and the live environment without a separate gatekeeper, think “SoD breach” first.
⚠ Common exam trap
The trap here is that candidates focus on the lack of testing or documentation, but the most critical control weakness is the violation of segregation of duties, as the developer both made the change and controlled its documentation, eliminating independent oversight.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inadequate segregation of duties between development and production environments
The developer bypassed the standard change approval process by making an emergency change directly to production, then retroactively documenting it as a normal change. This directly violates the principle of segregation of duties (SoD), as the same individual who implemented the change also controlled the documentation and approval trail, eliminating independent oversight. In a properly segregated environment, developers should not have direct write access to production systems without a separate change authorization and deployment step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Inadequate segregation of duties between development and production environments
Why this is correct
Direct production access by developers violates segregation of duties.
- ✗
Absence of a rollback plan for emergency changes
Why it's wrong here
Rollback plans are relevant but not the primary weakness highlighted.
- ✗
Insufficient testing of emergency changes before deployment
Why it's wrong here
Testing is important, but the main issue is unauthorized access.
- ✗
Lack of a formal change documentation policy
Why it's wrong here
Documentation was done, though improperly categorized.
Go deeper
Related to this question
About these practice questions
One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An IS auditor is evaluating the effectiveness of an organization's change management process. Which of the following is the most important control to verify during the audit?
easy- A.All changes are approved by the IT manager.
- B.Emergency changes are documented after implementation.
- ✓ C.A segregation of duties exists between development and production.
- D.Change requests are prioritized by business impact.
Why C: Segregation of duties between development and production environments ensures that code cannot be directly moved from development to production without independent review and testing. This control prevents unauthorized or untested code from affecting live systems, which is a fundamental principle of change management. Without this separation, a developer could introduce malicious or defective code directly into production, bypassing all quality and security checks.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.