Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is reviewing the job scheduling function for a mainframe environment that runs nightly batch processing. The auditor finds that the senior operator has standing access to modify production JCL and job schedules without a second approval. Which control should the auditor recommend to BEST mitigate the associated risk?

⚠ Common exam trap

The trap here is assuming that logging or documentation provides sufficient control when the real risk is the lack of a preventive segregation-of-duties mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement dual control over scheduling changes that affect production jobs.

The core issue is a segregation-of-duties gap: one senior operator can modify production JCL and schedules without independent approval. The most effective mitigation is a preventive control that requires two people to authorize and apply changes. Dual control ensures no single individual can alter critical batch processing, reducing the risk of both errors and fraud. Detective controls like logging are useful but do not stop the change from occurring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement dual control over scheduling changes that affect production jobs.

    Why this is correct

    Dual control requires two authorized individuals to approve and apply scheduling changes, preventing a single operator from unilaterally altering production processing. This directly addresses the segregation-of-duties weakness where one person can modify JCL and schedules. It is the most effective preventive control because it introduces independent verification before the change executes, reducing the risk of unauthorized or erroneous job modifications affecting financial or operational data.

  • ✗

    Enable logging of all JCL modifications and review the logs monthly.

    Why it's wrong here

    Logging and monthly review are detective controls that identify a problem after production jobs have already run incorrectly or maliciously. They do not prevent the senior operator from making unauthorized changes in the first place. While useful as a compensating or supporting control, they fail to mitigate the immediate risk of a single individual altering production schedules without oversight, so they are not the best recommendation here.

  • ✗

    Require the senior operator to document all schedule changes in a change log.

    Why it's wrong here

    Documentation alone relies on the same individual to self-report changes and provides no independent verification. A dishonest or careless operator could omit or falsify entries. This control does not prevent unauthorized modification and is weaker than a dual-control mechanism. It may support audit trails but does not adequately mitigate the risk of unilateral production scheduling changes.

  • ✗

    Restrict the senior operator's access to read-only for all production JCL.

    Why it's wrong here

    Removing all modify access may be impractical if the senior operator legitimately needs to respond to production emergencies. This could cause operational delays and force workarounds, such as sharing credentials, which would worsen the control environment. A blanket read-only restriction is excessive and does not address the need for controlled emergency changes. Dual control balances operational needs with risk mitigation.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.