CISA · Question #411
An organization is implementing a new enterprise resource planning (ERP) system. From a system performance management perspective, which of the following would pose the GREATEST concern for an IS…
The correct answer is A. The impact of the new system on existing enterprise infrastructure has not been evaluated. Failing to evaluate the impact on existing enterprise infrastructure is the greatest concern because it represents a fundamental, pre-implementation risk - if the new ERP overloads networks, servers, or integrated systems, it can cause widespread outages affecting the entire…
Question
An organization is implementing a new enterprise resource planning (ERP) system. From a system performance management perspective, which of the following would pose the GREATEST concern for an IS auditor?
Options
- AThe impact of the new system on existing enterprise infrastructure has not been evaluated
- BService level agreements (SLAs) for the new system have not been defined
- CPerformance metrics and dashboards have not been created
- DEscalation procedures for resolution of capacity and performance issues have not been
How the community answered
(30 responses)- A83% (25)
- B10% (3)
- C3% (1)
- D3% (1)
Explanation
Failing to evaluate the impact on existing enterprise infrastructure is the greatest concern because it represents a fundamental, pre-implementation risk - if the new ERP overloads networks, servers, or integrated systems, it can cause widespread outages affecting the entire organization, not just the ERP itself. This is a systemic risk that should be identified before go-live, making it an auditor's top priority.
Why the distractors fall short:
- B (SLAs not defined) is a governance gap but is correctable after deployment; the system can still function without them, whereas infrastructure incompatibility can cause immediate failure.
- C (No dashboards/metrics) is an operational monitoring gap - important for ongoing management, but you can create these post-implementation without catastrophic risk.
- D (No escalation procedures) is a process gap that affects response time to problems, but problems must first exist; undiscovered infrastructure conflicts can cause those problems in the first place.
Memory tip: Think of A as the "foundation" risk - you can always add SLAs, dashboards, and procedures later, but if the foundation (infrastructure compatibility) is broken, none of the rest matters. Auditors prioritize risks that could prevent a system from functioning at all over risks that affect how well it's managed once running.
Topics
Community Discussion
No community discussion yet for this question.