CISA · Question #173
Which of the following is MOST important for an IS auditor to verify when evaluating the upgrade of an organization's enterprise resource planning (ERP) application?
The correct answer is B. Security configurations were appropriately applied to the new version. ERP upgrades frequently reset or alter security configurations to vendor defaults, which may not meet the organization's required security posture. An IS auditor's primary concern is ensuring that security configurations - such as access controls, role-based permissions, and encr
Question
Which of the following is MOST important for an IS auditor to verify when evaluating the upgrade of an organization’s enterprise resource planning (ERP) application?
Options
- AApplication-related documentation was updated to reflect the changes in the new version
- BSecurity configurations were appropriately applied to the new version
- CUsers were provided security training on the new version
- DLessons learned analysis was documented after the upgrade
How the community answered
(23 responses)- A13% (3)
- B48% (11)
- C30% (7)
- D9% (2)
Explanation
ERP upgrades frequently reset or alter security configurations to vendor defaults, which may not meet the organization's required security posture. An IS auditor's primary concern is ensuring that security configurations - such as access controls, role-based permissions, and encryption settings - were correctly reapplied after the upgrade (B), because misconfigurations can expose sensitive business data and create compliance gaps. Updated documentation (A) is a good practice but not the highest audit priority. User security training (C) is operationally important but is a process, not a technical control. Lessons learned (D) is valuable for process improvement but does not affect the security posture of the upgraded system.
Topics
Community Discussion
No community discussion yet for this question.