What's changed: Initial version
5.2Evaluating operations and maintenance controls
Covers how an auditor evaluates the design and operating effectiveness of controls over job management, change management, configuration management, incident management, and backups, and diagnoses deficiencies such as uncontrolled emergency changes.
A system is operated for a long time after go-live, with daily job execution, program changes, incident response, and backups continuing. The auditor evaluates whether controls are designed into these operations and maintenance processes, records (trails) are kept, and they actually operate. In particular, the focus is on the effectiveness of controls that tend to become hollow in the field—whether changes that skip approval or records under the name of emergency response are rampant, and whether backups are not only taken but verified to be restorable—confirmed using evidence trails.
5.2.1Key controls in operations and maintenance
- Change management controls program/configuration changes to production through the sequence request → impact analysis → approval → testing → application → recording. The auditor reviews change requests and approval trails as evidence and evaluates whether changes without approval (uncontrolled changes) have reached production. For emergency changes too, it confirms that an approval/recording procedure—even after the fact—is defined and actually followed.
- Configuration management is a control that accurately grasps and maintains configuration information for hardware, software, and settings. The auditor confirms whether configuration information matches reality (reconciling the register against the actual assets), and if there is a discrepancy, suspects a missing detective control or hollowed-out operation. Job management concerns whether batch-job schedules, dependencies, and rerun procedures on abnormal termination are defined, and execution results (logs) are monitored.
- Incident management controls detection, recording, response to, and prevention of recurrence of incidents. The auditor evaluates whether incident records are kept without omission and whether escalation by severity and permanent countermeasures are implemented. For backups, what matters is not only periodic data capture but also verification that recovery from the captured backup is actually possible (restore testing) and a design such as offsite storage.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

