CISA - Information Systems Operations and Business Resilience (26% of the exam) - Section 4.1

Evaluate systems availability and capacity management, problem and incident management, and IT change, configuration and patch management.

Describe availability management and capacity management practices that keep systems performing within agreed thresholds. Evaluate incident management, problem management, change management and patch management controls to confirm that disruptions are resolved quickly and changes are authorised, tested and documented.

availability managementcapacity managementincident managementchange managementpatch management

Practice question for this objective

Free sampleInformation Systems Operations and Business Resiliencemedium

An IS auditor is reviewing problem management at a telecommunications provider. Recurring outages on a billing platform were each closed as separate incidents over the past quarter, but no problem record was raised and no root cause was identified. Service desk metrics show a 99 per cent incident closure rate. Which audit observation BEST captures the control weakness?

  • AIncident management is operating effectively because the closure rate exceeds the agreed service level target of 95 per cent across the quarter under review.
  • BProblem management is not linking recurring incidents to a problem record, so root causes remain unidentified and the recurrence pattern is not being acted upon. Correct
  • CThe service desk team should be trained to perform deeper root cause analysis on every incident before closing the ticket, so problem records become unnecessary.
  • DThe billing platform should be reclassified as a tier 1 system so that any recurrence of outages automatically triggers a major incident review chaired by the chief operating officer.
Distinguish incident management from problem management and recognise when recurring incidents indicate a missing problem management linkage. Incident management aims to restore service. Problem management aims to remove the underlying cause so the incident does not recur. A high closure rate is consistent with each recurrence being treated as a new incident while the defect persists. The auditor should observe that problem management is not linking recurring incidents to a problem record, which is the control responsible for breaking the cycle.

Why A is wrong: A high closure rate measures speed of ticket closure, not whether the underlying cause was addressed; the metric masks the absence of problem management and is a tempting but misleading conclusion.

Why B is correct: The control gap is the missing linkage from recurring incidents to a problem record; without it, recurrence is treated as fresh disruption each time and the underlying defect is never corrected, which the auditor should report as the primary weakness.

Why C is wrong: Conflating incident and problem management defeats their distinct purposes; incident management restores service quickly while problem management addresses root cause, and the auditor should preserve the separation rather than collapse it.

Why D is wrong: Reclassifying the platform is a management decision and addresses severity rather than the absence of problem management; tier changes do not by themselves cause root cause analysis to occur.

See more CISA practice questions, answers explained.

Exam traps in Information Systems Operations and Business Resilience

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • Change management records the as-is state of services, release management authorises individual modifications, and the CMDB schedules the packaging and timing of deployments.

    Why it is wrong: This swaps every responsibility, which is the most common candidate confusion; recording the as-is state is the CMDB's role, not change management's, and scheduling deployments is release management's role.

  • Release management approves what is changed, configuration management decides when changes deploy, and change management records the configuration items affected.

    Why it is wrong: This is tempting because the three practices share data, but it swaps every responsibility and would leave the change advisory board with no authorisation role.

  • Accept the explanation because container workloads are widely accepted as ephemeral and are commonly excluded from configuration management database scope in modern environments.

    Why it is wrong: Accepting an explanation without independent corroboration is reliance on management representation, which is insufficient audit evidence; ephemerality does not justify omission from the configuration baseline when assets are running in production.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.