CISA - Information Systems Operations and Business Resilience - Section 4.1

Assess operational log management, IT service level management and database management.

Understand the purpose of operational log management in capturing system events for monitoring, troubleshooting and audit trail integrity. Assess IT service level management - including SLA compliance - and database management controls to confirm that data is accessible, accurate and protected.

operational log managementservice level managementSLAdatabase management

Practice question for this objective

Free sampleInformation Systems Operations and Business Resiliencemedium

An IS auditor is reviewing the operational log management programme of a payments processor. Which characteristic of log records is MOST important for them to be useful as audit evidence in an investigation?

  • AThe logs are written in a human readable text format so that responders can open them in any editor without specialist tooling.
  • BThe logs are sampled monthly by the security team and the sampled records are summarised in a management dashboard for the chief information security officer.
  • CThe logs are protected against unauthorised modification and supported by demonstrable controls over their creation, transmission and retention. Correct
  • DThe logs are stored on the same server that generates the events so that timing differences between systems do not distort the recorded sequence.
Recognise that protected integrity across the log lifecycle, not format or volume, is what makes operational logs reliable audit evidence. Logs become reliable evidence only when the auditor can demonstrate that the records have not been altered between generation and review. Controls over generation, secure transmission, write once or hash protected storage and retention enforcement together establish that chain, which is why integrity is the dominant attribute.

Why A is wrong: Human readability is convenient for responders but does not by itself preserve evidential value, because plain text files can be modified silently after the fact.

Why B is wrong: Sampling and dashboards aid monitoring but the surviving records are still only as reliable as their source, so sampling alone does not raise evidential quality.

Why C is correct: Integrity over the full lifecycle is what allows a log to be relied upon as audit evidence, because the auditor must show the record reflects the original event.

Why D is wrong: Local storage actually weakens reliability because a compromised host can rewrite its own logs, which is why central, write protected collection is preferred.

See more CISA practice questions, answers explained.

More in this domain

Back to all Information Systems Operations and Business Resilience objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.