Isaca Certified Information Systems Auditor CISA Question # 7 Topic 1 Discussion

Isaca Certified Information Systems Auditor CISA Question # 7 Topic 1 Discussion

CISA Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1

A small IT department has embraced DevOps, which allows members of this group to deploy code to production and maintain some development access to automate releases. Which of the following is the MOST effective control?


A.

Enforce approval prior to deployment by a member of the team who has not taken part in the development.


B.

The DevOps team provides an annual policy acknowledgment that they did not develop and deploy the same code.


C.

Annual training reinforces the need to maintain segregation between developers and deployers of code


D.

The IT compliance manager performs weekly reviews to ensure the same person did not develop and deploy code.


Get Premium CISA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.