Certified in Risk and Information Systems Control (CRISC) — Question 1273
An organization allows programmers to change production systems in emergency situations. Which of the following is the BEST control?
Answer options
- A. Implementing an emergency change authorization process
- B. Periodically reviewing operator logs
- C. Limiting the number of super users
- D. Reviewing the programmers’ emergency change reports
Correct answer: A
Explanation
The best control in this situation is implementing an emergency change authorization process, as it provides a structured way to manage changes during critical moments, ensuring accountability and oversight. The other options, while important, do not directly control the emergency change process and may not provide immediate governance during urgent situations.