CISA - Information Systems Operations and Business Resilience - Section 4.1

Evaluate systems availability and capacity management, problem and incident management, and IT change, configuration and patch management.

Describe availability management and capacity management practices that keep systems performing within agreed thresholds. Evaluate incident management, problem management, change management and patch management controls to confirm that disruptions are resolved quickly and changes are authorised, tested and documented.

availability managementcapacity managementincident managementchange managementpatch management

Practice question for this objective

Free sampleInformation Systems Operations and Business Resiliencemedium

An IS auditor is reviewing problem management at a telecommunications provider. Recurring outages on a billing platform were each closed as separate incidents over the past quarter, but no problem record was raised and no root cause was identified. Service desk metrics show a 99 per cent incident closure rate. Which audit observation BEST captures the control weakness?

  • AIncident management is operating effectively because the closure rate exceeds the agreed service level target of 95 per cent across the quarter under review.
  • BProblem management is not linking recurring incidents to a problem record, so root causes remain unidentified and the recurrence pattern is not being acted upon. Correct
  • CThe service desk team should be trained to perform deeper root cause analysis on every incident before closing the ticket, so problem records become unnecessary.
  • DThe billing platform should be reclassified as a tier 1 system so that any recurrence of outages automatically triggers a major incident review chaired by the chief operating officer.
Distinguish incident management from problem management and recognise when recurring incidents indicate a missing problem management linkage. Incident management aims to restore service. Problem management aims to remove the underlying cause so the incident does not recur. A high closure rate is consistent with each recurrence being treated as a new incident while the defect persists. The auditor should observe that problem management is not linking recurring incidents to a problem record, which is the control responsible for breaking the cycle.

Why A is wrong: A high closure rate measures speed of ticket closure, not whether the underlying cause was addressed; the metric masks the absence of problem management and is a tempting but misleading conclusion.

Why B is correct: The control gap is the missing linkage from recurring incidents to a problem record; without it, recurrence is treated as fresh disruption each time and the underlying defect is never corrected, which the auditor should report as the primary weakness.

Why C is wrong: Conflating incident and problem management defeats their distinct purposes; incident management restores service quickly while problem management addresses root cause, and the auditor should preserve the separation rather than collapse it.

Why D is wrong: Reclassifying the platform is a management decision and addresses severity rather than the absence of problem management; tier changes do not by themselves cause root cause analysis to occur.

See more CISA practice questions, answers explained.

More in this domain

Back to all Information Systems Operations and Business Resilience objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.