nerdexam
CompTIA

CAS-001 · Question #351

Company A is purchasing Company B. Company A uses a change management system for all IT processes while Company B does not have one in place. Company B's IT staff needs to purchase a third party…

The correct answer is D. Use Company A's change management process during the evaluation of the new product. Since Company A is acquiring Company B and already has an established change management process, the correct next step is to fold Company B's activities into that existing framework immediately. Change management processes exist specifically to evaluate the security impacts of…

Integration of Computing, Communications and Business Disciplines

Question

Company A is purchasing Company B. Company A uses a change management system for all IT processes while Company B does not have one in place. Company B's IT staff needs to purchase a third party product to enhance production. Which of the following NEXT steps should be implemented to address the security impacts this product may cause?

Options

  • APurchase the product and test it in a lab environment before installing it on any live system.
  • BAllow Company A and B's IT staff to evaluate the new product prior to purchasing it.
  • CPurchase the product and test it on a few systems before installing it throughout the entire company.
  • DUse Company A's change management process during the evaluation of the new product.

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    6% (2)
  • D
    82% (28)

Explanation

Since Company A is acquiring Company B and already has an established change management process, the correct next step is to fold Company B's activities into that existing framework immediately. Change management processes exist specifically to evaluate the security impacts of new products and changes before they are introduced into a production environment. Purchasing the product first (A or C) bypasses the formal evaluation process. Allowing joint evaluation without a process (B) is informal and unstructured. Using Company A's change management process (D) ensures the third-party product is vetted through a formal, documented workflow that assesses risk, security impact, and approval gates before any purchasing or deployment decision is made.

Topics

#change management#merger acquisition#IT governance#third-party products

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice