certslothcertsloth
CISA/Topic 09

ISACA / Professional

Operational Controls, Databases and Resilience

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: A completed job is not necessarily a correct business result.

Must remember

Review scheduled processing for authorized definitions, dependencies, restart handling, completion and exception escalation. Interface controls should validate completeness, accuracy, duplicate detection and rejected transactions. Reprocessing must not duplicate business effects. Logs need synchronized time, protected retention and appropriate access.

Asset/configuration records should reflect deployed reality. Change, patch and release processes manage different aspects of modification; check approvals, testing, rollback and emergency review. Capacity/availability monitoring must connect technical thresholds to service requirements. Incident management restores service; problem management addresses underlying causes.

End-user spreadsheets and shadow IT can perform critical calculations without formal development controls. Assess access, formula/version integrity, input validation, backups and ownership proportionate to business impact. A tool’s small size does not make its financial or operational risk small.

Database controls include least privilege, integrity constraints, transaction consistency, backups, recovery tests and monitoring of privileged changes. Replication can reproduce corruption; historical recovery remains important. Evaluate BIA-derived priorities, RTO/RPO, dependencies and exercises across business continuity and disaster recovery. An SLA is a commitment, not proof the service actually met it.

Choose under exam pressure

Requirement Choice and reason
Payroll batch says success Verify totals, exceptions and downstream reconciliation.
Recurring outage after quick fixes Investigate problem/root-cause management.
Critical spreadsheet outside IT Apply proportionate ownership, access, integrity and recovery controls.

Traps

  • Job exit code zero does not prove data completeness.
  • A backup report is weaker than a successful representative restore test.

Active recall

1. Incident versus problem management?

Restore service versus address underlying causes.

2. Why control restarts?

To avoid duplicate or skipped transactions.

3. What is shadow IT risk?

Important services/data may bypass inventory, security and continuity controls.

4. Why protect log time accuracy?

Reliable event ordering and correlation depend on it.

5. Why derive recovery priorities from a BIA?

Business impact should determine restoration order and targets.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.