CISA · Question #612
During a review of an organization's IT capacity management process, an IS auditor should be MOST concerned if capacity planning:
The correct answer is B. Omitted changes to key business systems.. Omitting changes to key business systems is the most critical gap because capacity planning that ignores major system changes cannot accurately forecast resource needs - leading to outages, performance failures, or wasted spending. Business system changes (new applications, migra
Question
During a review of an organization's IT capacity management process, an IS auditor should be MOST concerned if capacity planning:
Options
- AWas reviewed once during the previous six months.
- BOmitted changes to key business systems.
- CLacked input from system administrators.
- DWas based on input from IT service management only.
How the community answered
(44 responses)- A2% (1)
- B77% (34)
- C14% (6)
- D7% (3)
Explanation
Omitting changes to key business systems is the most critical gap because capacity planning that ignores major system changes cannot accurately forecast resource needs - leading to outages, performance failures, or wasted spending. Business system changes (new applications, migrations, user growth) are the primary drivers of capacity demand, so excluding them renders the entire plan unreliable.
Why the distractors fall short:
- A - A six-month review cycle is arguably infrequent, but not inherently alarming; many organizations review capacity semi-annually without material risk.
- C - Lacking sysadmin input is a process weakness, but sysadmins are one of several valid data sources; the plan may still be adequate with input from other technical staff.
- D - IT service management is a legitimate and appropriate source of capacity input; relying on it alone is suboptimal but far less dangerous than ignoring actual system changes.
Memory tip: Think "garbage in, garbage out." If the inputs to the plan miss real business changes, the outputs (forecasts, budgets, provisioning) will be wrong regardless of how well the rest of the process runs. The most dangerous flaw is always missing data about reality, not process frequency or input source diversity.
Topics
Community Discussion
No community discussion yet for this question.