The incorrect statement is that the degree of risk determines whether a change request requires authorization. All changes should be authorized, although the level of approval, testing, documentation, and review may vary based on risk and impact. A low-risk change still requires some form of approval to preserve accountability and protect production integrity. Option A is correct because change management supports stable and improved operations. Option C is correct because repeatable and defined processes reduce errors, unauthorized changes, and disruption. Option D is generally correct because changes should be tested outside production before implementation, except under tightly controlled emergency procedures. Internal audit should test authorization, segregation of duties, testing, migration, emergency changes, and post-implementation review. Therefore, Option B is correct.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit