Certified in the Governance of Enterprise IT (CGEIT) — Question 149
A regulatory audit of an IT department has identified discrepancies between processes described in the procedures and what is actually done by system administrators. The discrepancies were caused by recent IT application changes. Which of the following would be the BEST way to prevent the recurrence of similar findings in the future?
Answer options
- A. Include the update of documentation within the change management framework.
- B. Assign the responsibility for periodic revisions and changes to process owners.
- C. Require each IT employee to confirm compliance with IT procedures on an annual basis.
- D. Establish high-level procedures to minimize process changes.
Correct answer: A
Explanation
The correct answer is A because integrating documentation updates into the change management framework ensures that any changes are consistently reflected in the procedures. Option B, while useful, does not guarantee that documentation will be updated with each change. Option C may help with compliance but does not address the root cause of documentation discrepancies. Option D may limit necessary changes rather than ensuring proper documentation practices.