Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca Exam CISA Topic 2 Question 94 Discussion

Actual exam question for Isaca's CISA exam
Question #: 94
Topic #: 2
[All CISA Questions]

Which of the following would provide the BEST evidence that a cloud provider's change management process is effective?

Show Suggested Answer Hide Answer
Suggested Answer: C

The results of a third-party review provided by the vendor would provide the best evidence that a cloud provider's change management process is effective, because it would be an independent and objective assessment of the vendor's compliance with best practices and standards for managing changes in the cloud environment. A third-party review would also include testing of the vendor's change management controls and procedures, and provide recommendations for improvement if needed.

Minutes from regular change management meetings with the vendor would not provide sufficient evidence, because they would only reflect the vendor's self-reported information and may not capture all the changes that occurred or their impact on the cloud services. Written assurances from the vendor's CEO and CIO would also not provide sufficient evidence, because they would be based on the vendor's own opinion and may not be verified by external sources. A copy of change management policies provided by the vendor would not provide sufficient evidence, because it would only show the vendor's intended approach to change management, but not how it is implemented or monitored in practice.


ISACA Cloud Computing Audit Program, Section 4.5: Change Management

Cloud Computing: Business Benefits With Security, Governance and Assurance Perspectives, Section 4.3: Change Management

Contribute your Thoughts:

Lynelle
3 months ago
I think C) The results of a third-party review provided by the vendor could also be strong evidence of effective change management.
upvoted 0 times
...
Magda
3 months ago
I agree with Whitley. Having documented minutes from meetings shows ongoing communication and oversight.
upvoted 0 times
...
Whitley
3 months ago
I think A) Minutes from regular change management meetings with the vendor would be the best evidence.
upvoted 0 times
...
Jolanda
3 months ago
The third-party review is the clear winner here. Unless the vendor's CEO and CIO are also world-class magicians, in which case I might consider their written assurances.
upvoted 0 times
...
Joaquin
3 months ago
A copy of the change management policies? Might as well ask the vendor to recite the policies while juggling chainsaws. The third-party review is the way to go, folks.
upvoted 0 times
Madalyn
2 months ago
I agree, a third-party review is more reliable than just trusting what the vendor says.
upvoted 0 times
...
Jade
2 months ago
Vendor's CEO and CIO could just be giving lip service, we need independent verification.
upvoted 0 times
...
...
Javier
3 months ago
Vendor's CEO and CIO assurances? More like hot air and empty promises. I'll take the third-party review any day!
upvoted 0 times
Janella
2 months ago
A copy of the change management policies could also give insight into how the process is structured.
upvoted 0 times
...
Harley
2 months ago
I think minutes from change management meetings would also be helpful to see the process in action.
upvoted 0 times
...
Carmen
3 months ago
I agree, third-party reviews are more reliable than promises from the CEO and CIO.
upvoted 0 times
...
...
Willow
3 months ago
The change management meeting minutes could be a good indicator, but I'm not sure they'd provide the full picture. The third-party review seems like the safest bet.
upvoted 0 times
...
Darell
4 months ago
I think the third-party review would give the best evidence of the change management process. The vendor's own policies and assurances might not be as objective.
upvoted 0 times
Lewis
2 months ago
D) A copy of change management policies provided by the vendor
upvoted 0 times
...
Sharee
2 months ago
I agree, a third-party review would be more objective.
upvoted 0 times
...
Olga
3 months ago
C) The results of a third-party review provided by the vendor
upvoted 0 times
...
Sherman
3 months ago
A) Minutes from regular change management meetings with the vendor
upvoted 0 times
...
...

Save Cancel