712-50 · Question #178
What oversight should the information security team have in the change management process for application security?
The correct answer is C. Information security should be aware of any significant application security changes and work. Option C correctly balances security oversight with operational reality: the information security team needs visibility into significant application security changes so they can assess risk, enforce policy, and collaborate on remediation - without becoming a bottleneck for…
Question
What oversight should the information security team have in the change management process for application security?
Options
- AInformation security should be informed of changes to applications only
- BDevelopment team should tell the information security team about any application security flaws
- CInformation security should be aware of any significant application security changes and work
- DInformation security should be aware of all application changes and work with developers before
How the community answered
(47 responses)- A6% (3)
- B4% (2)
- C74% (35)
- D15% (7)
Explanation
Option C correctly balances security oversight with operational reality: the information security team needs visibility into significant application security changes so they can assess risk, enforce policy, and collaborate on remediation - without becoming a bottleneck for every minor update.
Why the distractors fall short:
- A is too passive - being merely "informed" implies no active role or ability to influence outcomes before changes go live.
- B shifts the responsibility entirely to developers and only covers flaws, not proactive security design decisions made during change management.
- D overcorrects - requiring involvement in all application changes (not just security-relevant ones) is impractical and creates organizational friction without proportional security benefit.
Memory tip: Think of the information security team as a "significant filter" - they need enough visibility to catch high-risk changes early, but scoping their involvement to security-significant changes keeps the process efficient. If you see answer choices on oversight questions, watch for the word "all" (usually too broad) vs. "significant/meaningful" (usually the right calibration).
Topics
Community Discussion
No community discussion yet for this question.