Valid CISA Dumps shared by EduDump.com for Helping Passing CISA Exam! EduDump.com now offer the newest CISA exam dumps, the EduDump.com CISA exam questions have been updated and answers have been corrected get the newest EduDump.com CISA dumps with Test Engine here:
An organization uses an automated continuous integration/continuous deployment (CI/CD) tool to deploy changes to production. Which of the following would be an IS auditor's GREATEST concern in this situation?
Correct Answer: C
The greatest concern in a CI/CD environment is the accuracy of automated testing. Since code is deployed rapidly and often without manual intervention, weak or inaccurate test cases can allow vulnerabilities and defects to be pushed directly into production. Release frequency (A) and changing user requirements (D) are expected characteristics of agile/DevOps models and can be managed with governance. Delayed post-implementation reviews (B) may reduce oversight but do not directly undermine the core pipeline integrity. ISACA's DevOps guidance emphasizes that automated testing and validation of requirements must be thorough and reliable to ensure continuous deployment does not compromise quality or security.