account-Assessing Change Control and Change Management
Question # 00134029
Posted By:
Updated on: 11/14/2015 11:53 AM Due on: 12/14/2015

1.
Case 8.1 Assessing Change Control and Change Management (page 257).
Locate the article on the Internet and in two to three pages, answer questions 1–4 at the
end of the case.
CASE 8-1 Assessing Change Control and
Change Management
Read the article “Security Controls that Work” by Dwayne Melancon in the
2007 Issue, Volume 4 of the Information Systems Control Journal (available
http://www.isaca.org/Journal/Past-Issues/2007/Volume4/Pages/Security-Controls-That-Work1.aspx). Write a report that
answers the following questions:
1. What are the differences between high-performing organizations
and medium- and low-performing organizations in terms of normal
operating performance? Detection of security breaches? Percentage of
budget devoted to IT?
2. Which controls were used by almost all high-performing
organizations, but were not used by any low- or medium-performers?
3. What three things do high-performing organizations never do?
4. What metrics can an IT auditor use to assess how an organization is
performing in terms of change controls and change management? Why
are those metrics particularly useful?
Case 8.1 Assessing Change Control and Change Management (page 257).
Locate the article on the Internet and in two to three pages, answer questions 1–4 at the
end of the case.
CASE 8-1 Assessing Change Control and
Change Management
Read the article “Security Controls that Work” by Dwayne Melancon in the
2007 Issue, Volume 4 of the Information Systems Control Journal (available
http://www.isaca.org/Journal/Past-Issues/2007/Volume4/Pages/Security-Controls-That-Work1.aspx). Write a report that
answers the following questions:
1. What are the differences between high-performing organizations
and medium- and low-performing organizations in terms of normal
operating performance? Detection of security breaches? Percentage of
budget devoted to IT?
2. Which controls were used by almost all high-performing
organizations, but were not used by any low- or medium-performers?
3. What three things do high-performing organizations never do?
4. What metrics can an IT auditor use to assess how an organization is
performing in terms of change controls and change management? Why
are those metrics particularly useful?

-
Rating:
5/
Solution: account-Assessing Change Control and Change Management