CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An IS auditor is reviewing a change management process. Which TWO elements should be documented in a normal change request to ensure adequate governance? (Select TWO)
⚠ Common exam trap
CISA often tests the misconception that administrative details (requester name, vendor contact, budget) are governance elements — the exam expects candidates to identify the two elements that directly support change validation and risk mitigation: test plan and rollback plan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Test plan
A test plan (A) is correct because a normal change request must document how the change will be verified before implementation, including test cases, expected results, and acceptance criteria, which provides evidence that the change was validated and supports governance over change risk. A rollback plan (D) is correct because it defines the documented steps, triggers, and responsible parties for reverting the change if it fails or causes an incident, ensuring business continuity and recoverability are addressed before approval. Vendor contact information (B) is not a required element of a standard change request; it is only relevant for vendor-supported changes and is not part of the governance documentation for every change. The change requester's name (C) is typically captured as basic identification metadata, but it does not by itself ensure adequate governance of the change's risk and validation. Project budget remaining (E) relates to financial tracking and is not a required component of a change request's governance documentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Test plan
Why this is correct
A test plan evidences that the change was verified before release, confirming the requester identified how functionality and related controls would be validated. Without it, governance cannot demonstrate that the change works as intended or that regression risk was assessed prior to production deployment.
- ✗
Vendor contact information
Why it's wrong here
Vendor contact details support incident escalation and support cases, not governance of a normal change. They belong in supplier or contract records; a change request needs impact assessment, rollback plan, test evidence and approval, which demonstrate controlled authorisation and verification.
- ✗
Change requester's name
Why it's wrong here
The requester's name identifies who raised the change but proves nothing about assessment or authorisation. It is useful for traceability and follow-up, yet governance requires documented impact analysis, risk evaluation, testing and approval, which show the change was properly reviewed before implementation.
- ✓
Rollback plan
Why this is correct
A rollback plan documents how to restore the previous state if implementation fails, satisfying the governance requirement for a tested recovery path. Its absence leaves the organisation unable to reverse a failed change within agreed service levels, increasing downtime and data integrity risk.
- ✗
Project budget remaining
Why it's wrong here
Remaining project budget is financial tracking data, not change governance evidence. It matters for portfolio or cost reporting, but a normal change request must record impact assessment, rollback plan, testing results and approvals, which demonstrate that risk was evaluated and the change authorised.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.