Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An IS auditor is reviewing change management procedures and finds that standard changes are approved by the change manager without CAB review. What is the auditor's BEST conclusion?

⚠ Common exam trap

CISA often tests whether candidates understand that not all changes require CAB review, and the trap is assuming that any change without CAB approval is a control weakness, when standard changes are legitimately pre-approved.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

This is acceptable provided that standard changes are clearly defined and low-risk

Standard changes are pre-approved, low-risk, repeatable changes that follow a documented procedure, so it is acceptable for the change manager to approve them without CAB review provided they are clearly defined and low-risk. This aligns with ITIL and COBIT guidance that standard changes can be pre-authorized to avoid unnecessary bureaucracy. The auditor's best conclusion is that the process is acceptable under those conditions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    This is acceptable provided that standard changes are clearly defined and low-risk

    Why this is correct

    Standard changes are pre-authorised, low-risk, repeatable changes with documented procedures, so change manager approval without CAB review satisfies control objectives. The auditor's best conclusion is that this is acceptable provided the changes are clearly defined and genuinely low-risk.

  • ✗

    The change manager should be a member of the CAB

    Why it's wrong here

    Standard changes are pre-approved precisely because they are low-risk and routine, so CAB membership for the change manager adds no control. The finding concerns whether the classification is justified, not committee composition. This would be relevant if the manager also raised and approved the same change.

  • ✗

    The auditor should recommend that all changes go through CAB

    Why it's wrong here

    Routing every change through the CAB destroys the purpose of pre-authorised standard changes, which exist to avoid unnecessary review overhead for routine, low-risk work. The auditor should test whether the classification criteria are sound. Full CAB review would be correct only for normal or significant changes.

  • ✗

    This is a control weakness because all changes should be reviewed by the CAB

    Why it's wrong here

    Standard changes are pre-approved by definition, so CAB review is not required; the auditor should verify the change was correctly classified as standard. CAB review applies to normal changes, making this option tempting when the classification itself is the real control being tested.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.