1. A lack of automation with safeguards for DNS changes
2. Insufficient guardrails to enforce the Change Management process
3. Subversion of the Emergency Break Fix (EBF) process
It looks a lot like somebody tried to push their agenda (personal or organizational) and write points that suit their preferred solution rather than try to understand actual causes of the outage.These findings are essentially "Somebody made a mistake, let's remove accesses and/or put more controls on the process so that people are not even able to make a mistake".
This seems to be very low trust environment. My experience tells me the most likely course of action is that even if the problem is fixed, it is going to happen at the cost of more overhead in the process and making it even more low-trust, causing more damage in the long run.
You can apply this kind of flawed reasoning ("somebody made a mistake -- nobody can be trusted with it again") to any problem and soon nobody can do anything on their own. Productivity plummets. People are becoming disinterested in their work (try to be "engaged" when management takes all your tools away). Management blames people for not being able to do even basic things -- loosing even more trust and pushing even more solutions like that. Vicious cycle.
Take for example point #3.
How about figuring out WHY people need or feel they need to subvert EBF process? Isn't it rational to assume that if people have been subverting the process they might have actual reason to do so? Maybe their regular process is too onerous and they are using emergency process to meet deadlines? Maybe the effort should be directed at improving the regular process so that they don't have reason to subvert it?