CGEIT · Question #529
A regulatory audit of an IT department has identified discrepancies between processes described in the procedures and what is actually done by system administrators. The discrepancies were caused by r
The correct answer is C. Include the update of documentation within the change management framework.. To prevent discrepancies between documented procedures and actual practices due to IT application changes, the best approach is to integrate documentation updates directly into the change management framework.
Question
A regulatory audit of an IT department has identified discrepancies between processes described in the procedures and what is actually done by system administrators. The discrepancies were caused by recent IT application changes. Which of the following would be the BEST way to prevent the recurrence of similar findings in the future?
Options
- AAssign the responsibility for periodic revisions and changes to process owners.
- BRequire each IT employee to confirm compliance with IT procedures on an annual basis.
- CInclude the update of documentation within the change management framework.
- DEstablish high-level procedures to minimize process changes.
How the community answered
(32 responses)- A6% (2)
- B16% (5)
- C75% (24)
- D3% (1)
Why each option
To prevent discrepancies between documented procedures and actual practices due to IT application changes, the best approach is to integrate documentation updates directly into the change management framework.
Assigning responsibility for periodic revisions is a reactive approach and does not guarantee that documentation will be updated promptly when changes occur, leading to potential discrepancies in between revision cycles.
Requiring employees to confirm compliance annually is a control measure, but it does not address the root cause of the discrepancy, which is the failure to update documentation when underlying processes change.
Including the update of documentation within the change management framework ensures that whenever an IT application change occurs, the corresponding procedures and documentation are automatically reviewed and updated as part of the formal change process. This proactive approach prevents the divergence between "what is written" and "what is done" and ensures compliance with regulatory requirements by keeping documentation current.
Establishing high-level procedures to minimize process changes might seem appealing but can stifle necessary evolution and improvements, and it doesn't solve the problem of ensuring documentation matches actual processes when changes inevitably happen.
Concept tested: Change management and documentation synchronization
Source: https://learn.microsoft.com/en-us/azure/governance/blueprints/concepts/change-management
Topics
Community Discussion
No community discussion yet for this question.