CAS-002 · Question #83
After a system update causes significant downtime, the Chief Information Security Officer (CISO) asks the IT manager who was responsible for the update. The IT manager responds that it is impossible…
The correct answer is A. Implement an enforceable change management system. C. Enable user level auditing on all servers. Implementing a change management system paired with user-level server auditing creates both a pre-approval control gate and a forensic record to attribute administrative actions.
Question
After a system update causes significant downtime, the Chief Information Security Officer (CISO) asks the IT manager who was responsible for the update. The IT manager responds that it is impossible to know who did the update since five different people have administrative access. How should the IT manager increase accountability to prevent this situation from reoccurring? (Select TWO).
Options
- AImplement an enforceable change management system.
- BImplement a software development life cycle policy.
- CEnable user level auditing on all servers.
- DImplement a federated identity management system.
- EConfigure automatic updates on all servers.
How the community answered
(44 responses)- A80% (35)
- B2% (1)
- D7% (3)
- E11% (5)
Why each option
Implementing a change management system paired with user-level server auditing creates both a pre-approval control gate and a forensic record to attribute administrative actions.
An enforceable change management system requires changes to be requested, approved, documented, and linked to a responsible party before execution, creating an authoritative record that identifies who was authorized to perform each change.
A software development life cycle policy governs how software is built and released, not who performs live operational changes on production servers.
User-level auditing on servers captures the specific account, timestamp, and action for every administrative operation, providing the forensic trail needed to identify exactly which individual performed a given change after the fact.
Federated identity management consolidates authentication across systems but does not enforce change approval workflows or generate server-level activity audit logs.
Automatic updates remove human involvement entirely and produce uncontrolled, unattributed changes - directly worsening the accountability problem.
Concept tested: Change management and server auditing for accountability
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.